(edit)After the following logs were posted, the problems reappeared after a reboot. I followed your directions again from the beginning, and have reposted new logs after these originals.(/edit)First off, let me say how much I truly appreciate your advice and help.
I followed your directions exactly, but did not find a file named
gcfiusi.exe.
Logfile of HijackThis v1.99.1
Scan saved at 11:14:50 PM, on 8/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\PhoneTools\CapFax.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Nuker 2004\swn2.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\system32\rgxmya.exe
C:\Program Files\sder\dees.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Support.com\bin\jobcheck.exe
C:\Program Files\Support.com\bin\jobcheck.exe
C:\Program Files\Support.com\bin\tgshell.exe
C:\Program Files\Support.com\bin\tgshell.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Spyware Nuker] C:\Program Files\Spyware Nuker 2004\swn2.exe /h
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [nbqikf] C:\WINNT\system32\rgxmya.exe r
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ltho] C:\Program Files\sder\dees.exe
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\T3duZXIA\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
-------------
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:25:36 PM, 8/17/2005
+ Report-Checksum: A761D07A
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1CFB8B32-4053-4144-AF6F-1540EEC7F101} -> Spyware.Adlogix : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\SecureWin -> Spyware.Adlogix : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-3168526514-1597234714-2502462651-500\Software\VB and VBA Program Settings\VBouncer -> Spyware.VirtualBouncer : Cleaned with backup
HKU\S-1-5-21-3168526514-1597234714-2502462651-500\Software\VB and VBA Program Settings\VBouncer\Settings -> Spyware.VirtualBouncer : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
[780] C:\WINNT\system32\ienathlp.dll -> Spyware.Look2Me : Cleaned with backup
[876] C:\WINNT\system32\yahfjm.exe -> Trojan.Agent.cp : Cleaned with backup
[1220] C:\WINNT\system32\oydbse32.dll -> Spyware.Look2Me : Cleaned with backup
[1460] C:\WINNT\system32\wzhext.dll -> Spyware.Look2Me : Error during cleaning
[1516] C:\WINNT\system32\SPUTIL.DLL -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8ZG7W38D\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Y7K56DYR\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Y7K56DYR\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr2412 -> Spyware.WinAD : Cleaned with backup
C:\Program Files\AdDestroyer\AdDestroyer.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\HijackThis\backups\backup-20050814-020058-916.dll -> Spyware.E2Give : Cleaned with backup
C:\Program Files\HijackThis\backups\backup-20050814-020122-147.dll -> Spyware.E2Give : Cleaned with backup
C:\Program Files\HijackThis\backups\backup-20050814-020201-168.dll -> Spyware.E2Give : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/cdap.exe.000 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/cfgmgr52.dll.000 -> Spyware.BookedSpace : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/df_kmd.sys.000 -> Trojan.Rootkit.Agent.af : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/dsr.dll.000 -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/dsr.exe.000 -> Trojan.Imiserv.c : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/lanaap.exe.000 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/Nail.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/salm.exe.000 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/salmhook.dll.000 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/tyfeuaraa.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/visfxun.exe.000 -> TrojanDownloader.VB.kd : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/yqubq.dat.000 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508140956.zip/~uni.001 -> Spyware.PurityScan : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/AdDestroyer.exe.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/Nail.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/PopOops.dll.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/PopOops2.dll.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/SWLAD1.dll.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/SWLAD2.dll.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/VirtualBouncer.exe.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141341.zip/wintask.exe.000 -> TrojanDownloader.Small.abd : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141401.zip/AppWrap[1].exe.000 -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141401.zip/Nail.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508141401.zip/VirtualBouncer.exe.000 -> Spyware.VirtualBouncer : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/adv.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/adx.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/AUNPS2.dll.000 -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/AutoUpdaterInstaller[2].exe.000 -> TrojanDownloader.Apropo.g : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/auto_update_uninstall.exe.000 -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/auto_update_uninstall.exe.001 -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/b.com.000 -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/bargains.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/bbchk.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/cashback.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/cb.exe.000 -> Spyware.CashBack : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/cfgmgr52.dll.000 -> Spyware.BookedSpace : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/cxtpls_loader.exe.000 -> TrojanDownloader.Apropo.ae : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/dsr.dll.000 -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/dsr.exe.000 -> Trojan.Imiserv.c : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exdl.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exdl1.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exdl2.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exdl3.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exul.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exul1.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/exul3.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/ezPopStub.exe.000 -> Adware.eZula : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/flash.exe.000 -> Spyware.CashBack : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/installer_MARKETING58.exe.000 -> TrojanDownloader.Adload.a : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/javexulm.vxd.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/lapasf.exe.000 -> Spyware.Apropos : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/mqexdlm.srg.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/msbe.dll.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/mscb.dll.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/Nail.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/nls.exe.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/nvms.dll.000 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/SSK39.exe.000 -> TrojanDropper.Small.qn : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/tyfe0CA6.000 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Spyware Nuker 2004\backup\200508151221.zip/tyfeuaraa.exe.000 -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3168526514-1597234714-2502462651-500\Dc2.exe -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3168526514-1597234714-2502462651-500\Dc3.exe -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3168526514-1597234714-2502462651-500\Dc4.exe -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3168526514-1597234714-2502462651-500\Dc5.exe -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\S-1-5-21-3168526514-1597234714-2502462651-500\Dc6.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINNT\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINNT\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINNT\etb\pokapoka61.exe -> TrojanDropper.Agent.qz : Cleaned with backup
C:\WINNT\etb\xud2f.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINNT\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINNT\ru.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINNT\system32\AUNPS2.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINNT\system32\fxqufc.exe -> Spyware.Adstart : Cleaned with backup
C:\WINNT\system32\fxquff.exe -> Spyware.Adstart : Cleaned with backup
C:\WINNT\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\ienathlp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\iretppui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\kdaod.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINNT\system32\kjdfr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\kpdfr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\lapaE8D6 -> Spyware.Apropos : Cleaned with backup
C:\WINNT\system32\LPFPX7.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mdcms.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\meencode.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\mssjte.exe -> TrojanSpy.VB.eh : Cleaned with backup
C:\WINNT\system32\nsw7.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINNT\system32\nymsevt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\oBkley.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\oydbse32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\PopOops.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINNT\system32\PopOops2.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINNT\system32\pttorsvc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\redit.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINNT\system32\runpdx.exe -> TrojanSpy.VB.eh : Cleaned with backup
C:\WINNT\system32\SPUTIL.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINNT\system32\SWLAD1.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINNT\system32\SWLAD2.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINNT\system32\wdsdmod.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\wfsjfkl.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINNT\system32\wintask.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINNT\system32\yahfjm.exe -> Trojan.Agent.gp : Cleaned with backup
C:\WINNT\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\WINNT\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINNT\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\WINNT\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINNT\Temp\Del17.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\WINNT\Temp\Del21.tmp -> Spyware.180Solutions : Cleaned with backup
C:\WINNT\Temp\MediaAccessInstPack.exe -> Spyware.WinAD : Cleaned with backup
C:\WINNT\Temp\res18.tmp -> Spyware.180Solutions : Cleaned with backup
C:\WINNT\tyfeuaraa.exe -> Adware.BetterInternet : Cleaned with backup
::Report End
END OF FIRST CLEANING ATTEMPT
Edited by jswafford, 18 August 2005 - 08:04 AM.