Sry it took me forever .. scan took all night plus i was working at a golf tournament .. but here are the things .. it looks like its helping already so Thx for so much help you have givin to me
Hijack this first then the ewido
Logfile of HijackThis v1.99.1
Scan saved at 3:16:36 PM, on 8/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\AlienAutopsy\TEKS_Service.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\ivbaaue.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\EMPORER scarygary\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant =
http://www.sharempeg.com/find/R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch =
http://www.sharempeg.com/find/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lookfor.cc?pin=37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lookfor.cc?pin=37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://lookfor.cc/sp.php?pin=37049R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lookfor.cc?pin=37049R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.alienware.com/R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WinStat - {0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF} - C:\WINDOWS\System32\WinStat13.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tlocab] C:\WINDOWS\System32\belyjv.exe
O4 - HKLM\..\Run: [QP] C:\documents and settings\emporer scarygary\local settings\temp\QP.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [second] C:\Documents and Settings\EMPORER scarygary\Desktop\l2mfix\second.bat
O4 - HKLM\..\Run: [oruvitn] c:\windows\system32\ivbaaue.exe r
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [woii] C:\PROGRA~1\COMMON~1\woii\woiim.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search -
http://bar.mywebsear...?p=ZNxmk596YYUSO8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9425.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=Http://www.alienware.com
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone:
http://www.neededware.comO15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: 206.161.125.149 (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: NDWCab -
http://www.neededware.com/ndw4.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {AD684060-16D6-40C3-AF27-53956783430D} -
http://www.xpehbam.biz/exploit.exeO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -
http://ax.phobos.app.../ITDetector.cabO16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} -
http://deposito.host...ler/1072526.exeO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
http://chat.msn.com/...s/msnchat45.cabO20 - Winlogon Notify: f3dsl - lsd_f3.dll (file missing)
O21 - SSODL: eplrr - {5BD377BA-5F05-42D4-9393-09ED57CA4BB0} - C:\WINDOWS\System32\eplrr3.dll (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ProductivIT Service (ProductivITService) - DynTek, Inc. - C:\Program Files\AlienAutopsy\TEKS_Service.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing)
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 5:06:17 AM, 8/13/2005
+ Report-Checksum: 7619516
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6CC1C91A-AE8B-4373-A5B4-28BA1851E39A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\winlink.ViewSource -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\winlink.ViewSource\CLSID -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\winlink.ViewSource\CurVer -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\HbTools -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\HbTools\HbTools -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\HbTools\HbTools\Install -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\HbTools\Install -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\HbTools\Install\CmpMap -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CC1C91A-AE8B-4373-A5B4-28BA1851E39A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Spyware.KeenValue : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Spyware.BetterInternet : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\Bundles -> Spyware.SecondThought : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\dsktb -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\dsktb\DesktopToolbar -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\HbTools -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\HbTools\HbTools -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\HbTools\HbTools\Install -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1801674531-343818398-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
[208] C:\WINDOWS\system32\lsd_f3.dll -> TrojanSpy.Banker.md : Cleaned with backup
[688] VM_00900000 -> Adware.BetterInternet : Error during cleaning
[788] c:\windows\system32\ouslawr.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.15:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.32:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.38:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.39:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.84:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.85:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.86:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.90:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.95:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.96:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.97:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.98:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.99:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.100:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.101:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.102:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.103:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.104:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.105:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.106:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.107:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.108:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.109:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.110:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.111:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.120:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.121:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.122:C:\Documents and Settings\EMPORER scarygary\Application Data\Mozilla\Firefox\Profiles\rhkecjsf.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Application Data\winlink\winlink.dll -> TrojanDownloader.WinShow.l : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer scarygary@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Desktop\RAG_SETUP0615.EXE -> Backdoor.Ifinst : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Desktop\SAK_SETUP0621.EXE -> Backdoor.Ifinst : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\installer_MARKETING35.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\adlinstallwin32.exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\akcore.dll -> Spyware.Coreak : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\aklsp.dll -> TrojanDownloader.Agent.br : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\akrules.dll -> TrojanDownloader.Agent.bt : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\aoll.exe -> Trojan.Hooker.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\bw2.exe -> TrojanDropper.Small.of : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Cookies\emporer scarygary@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Cookies\emporer
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Cookies\emporer
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\dSJn7w9Og.exe -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\fEGhYef.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\i22.tmp -> TrojanDownloader.Totavel.a : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\i3.tmp -> TrojanDownloader.Totavel.a : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\i42.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\i82.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\ICD3.tmp\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\II22.exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\iinstall.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\lJ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\ms4.tmp -> TrojanDownloader.Small.wk : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Patch221.exe -> TrojanDropper.Agent.r : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\remove.exe -> TrojanDownloader.Keenval.f : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\RzCs42A6.exe -> Spyware.WinFetcher : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\targetsaver.exe -> TrojanDownloader.TSUpdate.f : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.fr0C3E -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.fr189A -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.fr6914\WSup.exe -> Spyware.Wintol : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.fr6914\WToolsA.exe -> Spyware.Wintol : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.fr6914\WToolsS.exe -> Spyware.Wintol : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\gykhxlmu.rmr -> Spyware.IBIS : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\nzqlihv.wzg -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\PIB.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\radio.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\TBPS.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\temp.frAB9C\xlmurin.wzg -> Spyware.IBIS : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI13D6.tmp\wupdt.exe -> TrojanDownloader.Intexp.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI3438.tmp\wupdt.exe -> TrojanDownloader.OneClickNetSearch.h : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI3D49.tmp\wupdt.exe -> TrojanDownloader.OneClickNetSearch.h : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI76E2.tmp\wupdt.exe -> TrojanDownloader.Intexp.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI7E97.tmp\wupdt.exe -> TrojanDownloader.Intexp.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI91D.tmp\wupdt.exe -> TrojanDownloader.Intexp.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\THI95D.tmp\wupdt.exe -> TrojanDownloader.Intexp.b : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Toolbar3.cab/IExploreSkins.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Toolbar3.cab/TBPS.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Toolbar3.cab/radio.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\Toolbar3.cab/toolbar.dll -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\whenu.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\ZNO\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
C:\Documents and Settings\EMPORER scarygary\Local Settings\Temp\~apropos0\ph.exe -> TrojanDownloader.Apropo.p : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Cookies\incaseofproblem@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Local Settings\Temp\adlinstallwin32.exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Local Settings\Temp\f9VkXIs.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Local Settings\Temp\ln_reco.exe -> TrojanDropper.Agent.ch : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Local Settings\Temporary Internet Files\Content.IE5\6RSTOBS1\id201[1].exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\Documents and Settings\incaseofproblem\Local Settings\Temporary Internet Files\Content.IE5\S309CHGV\clicks[1].dll -> Adware.MidADle : Cleaned with backup
C:\io.dll -> Trojan.Delf.cj : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Common Files\woii\woiia.exe -> TrojanDownloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\woii\woiil.exe -> TrojanDownloader.TSUpdate.j : Cleaned with backup
C:\Program Files\Common Files\woii\woiip.exe -> Spyware.Xupiter : Cleaned with backup
C:\Q121103.exe -> TrojanDownloader.WinShow.g : Cleaned with backup
C:\WINDOWS\anvmkpw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1018.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\YSBactivex.dll -> TrojanDownloader.IstBar.gk : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\EPXActiveX.ocx -> TrojanDropper.Agent.or : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1018.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1018.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\dexGB586.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\epx.exe -> TrojanDownloader.Lastad.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\YSBactivex.dll -> TrojanDownloader.IstBar.gb : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\homepage.htm -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\IFinst25.exe -> Backdoor.Ifinst : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\odbs.log -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\Q329170.log:fyyxp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Q329834.log:yzqcj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Q810833.log:qsbil -> TrojanDownloader.Agent.cd : Cleaned with backup
C:\WINDOWS\svchost.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\svcproc.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\aly.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ATPartners.dll -> TrojanDownloader.Rameh.c : Cleaned with backup
C:\WINDOWS\system32\dfmvz.exe -> TrojanDropper.Agent.jl : Cleaned with backup
C:\WINDOWS\system32\dfmvzndw30101lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\DrPMon.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\epx30104.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\id113.exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\WINDOWS\system32\iesprt.sys -> TrojanSpy.Banker.md : Cleaned with backup
C:\WINDOWS\system32\in10b6s.dll -> TrojanDropper.Mudrop.m : Cleaned with backup
C:\WINDOWS\system32\lsd_f3.dll -> TrojanSpy.Banker.md : Cleaned with backup
C:\WINDOWS\system32\mseggo.gif -> TrojanSpy.Delf.dx : Cleaned with backup
C:\WINDOWS\system32\msnimk.gif -> Spyware.Ipend : Cleaned with backup
C:\WINDOWS\system32\ouslawr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ozakcv.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\pfri.exe -> TrojanDownloader.Lastad.d : Cleaned with backup
C:\WINDOWS\system32\Searchx.htm -> Spyware.TwainTech : Cleaned with backup
C:\WINDOWS\system32\ssab.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\telnet.exe.tmp -> Backdoor.Small.cj : Cleaned with backup
C:\WINDOWS\system32\tkldq.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tkldqndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\umnizzu.exe -> TrojanDownloader.Lastad.i : Cleaned with backup
C:\WINDOWS\system32\umnizzundw301lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\WinStat11.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\zyqgqa.exe -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\system32\zyqgqaaeg06.dll -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\wfpmhurniqd.exe -> Adware.BetterInternet : Cleaned with backup
::Report End