Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Lots of Pop-Ups [RESOLVED]


  • This topic is locked This topic is locked

#16
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hmm, updates work fine here...

Try next first:

* Download: Hoster
Unzip hoster to an own folder, eg C:\Hoster
Start Hoster.exe, click 'Restore Original Hosts' and click OK.

Try to update again afterwards.
If that doesn't work, try it without updating then.
Also, I want you to perform an adaware scan also in safe mode AFTER you ran ewido in safe mode. :tazz:

Edit.. also disable your norton firewall and try to update again.

Edited by miekiemoes, 25 August 2005 - 12:40 PM.

  • 0

Advertisements


#17
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Now that I think of it, I think I did skip the CCleaner step from a few posts ago. Sorry about that. I think I just deleted files and then did ewido.

I'm waiting for your reply, so just respond to my previous post. I don't want to go forward yet, just in case there's a problem.
  • 0

#18
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Disregard my last post. I didn't realize that this thread already filled up a page.
  • 0

#19
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
First, I forgot to run the adaware in safe mode.

Second, during the hijackthis in safe mode I did not find:
O4 - HKLM\..\Run: [kufjuzs] C:\WINDOWS\system32\sbngtws.exe r

Third, I did everything else correctly.
  • 0

#20
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:12:19 PM, 8/25/2005
+ Report-Checksum: 629C08C7

+ Scan result:

HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
[956] C:\WINDOWS\system32\duojosi.exe -> Trojan.Agent.cp : Cleaned with backup
[1100] VM_00FC0000 -> Adware.BetterInternet : Error during cleaning
C:\Apps\l2mfix\backup.zip/sbsbkup.dll -> Spyware.Look2Me : Cleaned with backup
C:\Apps\l2mfix\backup.zip/vomredir.dll -> Spyware.Look2Me : Cleaned with backup
C:\Apps\l2mfix\backup.zip/wjnrnr.dll -> Spyware.Look2Me : Cleaned with backup
C:\Apps\l2mfix\backup.zip/guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00038189.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038192.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038195.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038198.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038201.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038204.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038229.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038232.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038235.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038238.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038241.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038244.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038260.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038263.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038266.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038269.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038272.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038275.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038277.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038278.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038279.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038280.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038281.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038282.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038283.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038305.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038308.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038311.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038314.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038317.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038320.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038322.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038330.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038337.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038345.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038348.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038351.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038354.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038357.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038360.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038380.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038383.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038386.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038389.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038392.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038395.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038398.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038432.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038440.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038443.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038446.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038449.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038452.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038455.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038494.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038497.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038500.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038503.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038506.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038509.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038511.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038512.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038513.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038514.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038515.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038516.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038557.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038560.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038563.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038566.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038569.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038572.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038580.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038582.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038584.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038585.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038586.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038587.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038588.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038589.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038590.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038592.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038593.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038595.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038603.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038606.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038609.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038612.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038615.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038618.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038624.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038625.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038626.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038628.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038629.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038630.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038631.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038632.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038633.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038655.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038658.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038661.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038664.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038667.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038670.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038680.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038683.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038684.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038685.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038686.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038687.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038688.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038702.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038705.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038708.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038711.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038714.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038717.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038735.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038738.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038741.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038744.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038747.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038750.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038767.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038770.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038773.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038776.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038779.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038782.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038784.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038785.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038786.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038787.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038811.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038812.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038813.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038814.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038822.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038825.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038828.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038831.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038834.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038837.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038856.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038859.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038862.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038865.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038868.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038871.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038887.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038890.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038893.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038896.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038899.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038906.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038910.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038911.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038912.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038913.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038922.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038923.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038924.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038925.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038941.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038944.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038947.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038950.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038953.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038956.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038974.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038977.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038980.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038983.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038986.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038989.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00038991.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038992.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038993.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00038994.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039016.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039017.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039018.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039019.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039020.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039021.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039022.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039023.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039034.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039035.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039036.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039051.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039054.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039057.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039060.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039063.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039066.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039069.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039070.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039071.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039085.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039088.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039091.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039095.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039098.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039101.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039120.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039124.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039127.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039130.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039133.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039136.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039155.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039158.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039161.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039164.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039167.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039170.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039172.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039173.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039174.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039175.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039177.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039178.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039179.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039180.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039181.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039182.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039183.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039184.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039185.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039186.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039205.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039208.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039211.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039214.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039217.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039220.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039237.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039240.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039243.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039246.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039249.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039252.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039274.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039277.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039279.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039280.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039282.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039284.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039287.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039290.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039293.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039314.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039317.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039320.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039323.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039326.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039329.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039332.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039333.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039334.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039338.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039339.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039340.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039341.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039358.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039361.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039364.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039367.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039370.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039373.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039399.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039402.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039405.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039408.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039411.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039414.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039416.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039417.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039421.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039422.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039423.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039424.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039425.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039426.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039431.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039432.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039433.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039442.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039444.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039446.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039449.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039451.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039452.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039453.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039454.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039462.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039465.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039468.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039471.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039476.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039480.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039497.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039500.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039503.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039506.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039509.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039512.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039518.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039532.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039535.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039538.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039541.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039544.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039547.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039565.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039568.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039571.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039574.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039577.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039580.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039597.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039600.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039603.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039606.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039609.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039612.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039627.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039630.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039633.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039636.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039639.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039642.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039657.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039660.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039663.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039666.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039669.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039672.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039695.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039698.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039701.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039704.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039707.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039710.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039715.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039725.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039728.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039729.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039730.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039731.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039732.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039733.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039753.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039756.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039759.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039762.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039765.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039768.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039789.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039792.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039795.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039798.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039801.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039804.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039820.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039823.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039826.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039829.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039832.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039835.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039855.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039858.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039861.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039865.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039868.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039871.TXT -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00039876.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039877.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039878.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00039879.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\system32\akbkp.dat -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YL6TU7K7\proxy_inst[1].exe -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\system32\duojosi.exe -> Trojan.Agent.ay : Cleaned with backup
C:\WINDOWS\system32\skytown.exe -> TrojanSpy.VB.eh : Cleaned with backup
C:\WINDOWS\tbhnhyzrjbt.exe -> Adware.BetterInternet : Cleaned with backup


::Report End
  • 0

#21
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Logfile of HijackThis v1.99.1
Scan saved at 8:23:57 PM, on 8/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\program files\umsd tools2.33\umsd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Apps\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PLoader] c:\program files\umsd tools2.33\umsd.exe sys_auto_run C:\Program Files\UMSD Tools2.33
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [2PNKAD] "C:\WINDOWS\System32\cxtpls_loader.EXE" /PC=CP.AOP2
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\gs4sl4.exe reg_run
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#22
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
One more thing! When I startup my computer, I keep getting an error about "nail.exe".

I searched for it and the location is

C:/WINDOWS/Prefetch/NAIL.EXE-25042152.pf

I remember you said there might be an error with "nailfix.exe" so perhaps this is it :tazz:
  • 0

#23
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
See...how important that it was you don't miss a step? :tazz: Now you performed everything correctly without missing a step with success. :)

Don't worry about that error.. that's good news.
Checking and fixing next line in hijackthis solves the problem:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Now let's deal with qoologic..

Download Find Q.zip and save it to your desktop.
http://forums.net-in...=post&id=153912

Extract (unzip) the files inside into their own folder called Find Q.
Look here how to unzip/extract properly:
http://metallica.gee...xplanation.html
Open the Find Q-folder.
Locate and double-click the Find Q.bat to run it.
Wait until notepad opens and copy and paste the content in your next reply.

Also, I want to compare with another tool for qoologic.. so try this one also:
Download FindQoologic.zip save it to your Desktop.
http://forums.net-in...=post&id=134981

Extract (unzip) the files inside into their own folder called FindQoologic.
Open the FindQoologic folder. Preferable to your desktop.
Locate and double-click the Find-Qoologic.bat file to run it.
Wait until a text opens.
Post this in your next reply

I need two logs in your next reply. :)

Edited by miekiemoes, 26 August 2005 - 12:07 AM.

  • 0

#24
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL is a windows file...

C:\WINDOWS\SYSTEM32\CONRES.CPL
C:\WINDOWS\SYSTEM32\DATADX.DLL
C:\WINDOWS\SYSTEM32\NAOAJ.DLL
C:\WINDOWS\SYSTEM32\JSKSSKF.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\KIPI.EXE

»»»»»2K XP 9X and ME Misc check's...


»»»»» 9X and ME check's...
  • 0

#25
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi, you didn't use findqoologic as I asked you.
There were two searchtools in my previous post.. so please use this one also:

Download FindQoologic.zip save it to your Desktop.
http://forums.net-in...=post&id=134981

Extract (unzip) the files inside into their own folder called FindQoologic.
Open the FindQoologic folder. Preferable to your desktop.
Locate and double-click the Find-Qoologic.bat file to run it.
Wait until a text opens.
Post this in your next reply


The reason I'm asking you this is because I want to compare things. :tazz:
  • 0

Advertisements


#26
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
I've opened the FindQoologic about 15 minutes ago and there's no notepad yet. I'm going to close it, shut down and go to sleep. All it says is:

"Be patient this will take awhile.
Just wait until a text opens please.
If you see an error message,
close this command prompt and read the readme.txt file
Disregard the parameters message"

If it needs more time, then I'll have to do it tomorrow. If it shouldn't take that long, then tell me what I need to do. Thanks :)

Just to clarify, I didn't forget about the FindQoologic. :tazz:

Edited by mike-like, 26 August 2005 - 12:57 AM.

  • 0

#27
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Ok, no problem... we'll deal with what we have now.
This next fix only takes 5 minutes... and when done, normally all your problems must be solved :tazz:

* Download Killbox.
Unzip it and Click killbox.exe.
Select the option "Delete on reboot".

Now copy the next bold:

C:\WINDOWS\SYSTEM32\CONRES.CPL
C:\WINDOWS\SYSTEM32\DATADX.DLL
C:\WINDOWS\SYSTEM32\NAOAJ.DLL
C:\WINDOWS\system32\gs4sl4.exe
C:\WINDOWS\System32\cxtpls_loader.EXE
C:\WINDOWS\SYSTEM32\JSKSSKF.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\KIPI.EXE


Open 'file' in the killboxmenu on top and choose Paste from clipboard

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines must be there together if the files are present!

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you don't get that message, reboot manually.
Click No at the Pending Operations prompt.

Your computer must reboot now.

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

O4 - HKLM\..\Run: [2PNKAD] "C:\WINDOWS\System32\cxtpls_loader.EXE" /PC=CP.AOP2
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\gs4sl4.exe reg_run


* Click on Fix Checked when finished and exit HijackThis.

Reboot once again and post a new hijackthislog together with a log of Find Q. :)

Edited by miekiemoes, 26 August 2005 - 01:14 AM.

  • 0

#28
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Logfile of HijackThis v1.99.1
Scan saved at 6:26:11 PM, on 8/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\program files\umsd tools2.33\umsd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Real\RealOne Player\RealPlay.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Apps\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PLoader] c:\program files\umsd tools2.33\umsd.exe sys_auto_run C:\Program Files\UMSD Tools2.33
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_03\bin\npjpi141_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#29
mike-like

mike-like

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL is a windows file...


»»»»»2K XP 9X and ME Misc check's...


»»»»» 9X and ME check's...
  • 0

#30
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

Well, I see a clean hijackthislog. :tazz:

Perform a full scan with an updated Adaware SE and/or Spybot S&D to get rid of the leftovers.
If you don't have those programs yet, you can find the downloadlocations in my sig.

To keep this clean in the future, I would suggest the following things:

Install Spywareblaster
SpywareBlaster doesn`t scan and clean for so-called spyware, but prevents it from being installed in the first place. It blocks the popular spyware ActiveX controls, and also prevents the installation of any of them via a webpage.

Avoid illegal sites, because that's where most malware is present.

Let your antispywarescanner(s) scan frequently and don't forget to update before.

And I do suggest you perform an online virusscan once in a while. (Housecall and/or Bitdefender). Because what one virusscanner can't find another one maybe can.
Also make sure that your virusscanner, the one that is installed on your system is always up to date!

Make sure your windows has the latest updates: http://windowsupdate.microsoft.com/

If you are having XP SP2, read here how to configure Security Features for Internet Explorer:
http://www.microsoft...xp/iesecxp.mspx

More info on how to prevent malware you can also find here (By Tony Klein)

Happy surfing again! :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP