cheers for that, here's the new logs
Logfile of HijackThis v1.99.1
Scan saved at 21:58:28, on 11/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\SAMSUNG\SENS Keyboard V4 Launcher\SENSKBD.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\VoyagerTest\fts.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\kris\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [xiqesab] C:\WINDOWS\System32\aikiqvv.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [vmcleaner] gxlib.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [syszm32.exe] C:\WINDOWS\system32\syszm32.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\Stopzilla.exe /autostart
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SENS Keyboard V4 Launcher] "C:\Program Files\SAMSUNG\SENS Keyboard V4 Launcher\SENSKBD.EXE"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [mswspl] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Hot_Tarts] C:\Program Files\Mpb\Dialers\Hot_Tarts\Hot_Tarts.exe /dontdial
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [AutoLoader2w5t1JbUPYLX] "C:\WINDOWS\System32\atmmp11n.exe" /HideDir /HideUninstall /PC="AM.ALGX"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\Adstartup.exe
O4 - HKLM\..\Run: [23mR37e] atmmp11n.exe
O4 - HKLM\..\Run: [1234abcd] c:\windows\system32\1234abcd.exe /install
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Jessops Insert Detect] C:\Program Files\Jessops\Picture Suite\InsDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...84/mcinsctl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1100737720177O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1125345354503O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -
http://download.zone...canner37240.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,21/mcgdmgr.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
AboutBuster 5.0 reference file 31
Scan started on [11/09/2005] at [20:24:20]
------------------------------------------------
Streams(ADS) not scanned: System not NTFS
------------------------------------------------
Removed File! : C:\Windows\uymaf.dat
Removed File! : C:\Windows\mdbatt.dat
Removed File! : C:\Windows\wnzoz.dat
Removed File! : C:\Windows\hpdzv.dat
Removed File! : C:\Windows\ndnzqo.dat
Removed File! : C:\Windows\zaqmw.dat
Removed File! : C:\Windows\lojwvk.dat
Removed File! : C:\Windows\dpckpv.dat
Removed File! : C:\Windows\hxjem.dat
Removed File! : C:\Windows\icgnsq.dat
Removed File! : C:\Windows\aczsvs.dat
Removed File! : C:\Windows\lyyol.dat
Removed File! : C:\Windows\wajhh.dat
Removed File! : C:\Windows\micida.dat
Removed File! : C:\Windows\fjvnxc.dat
Removed File! : C:\Windows\ogxzm.dat
Removed File! : C:\Windows\fvwjzr.dat
Removed File! : C:\Windows\ywhptb.dat
Removed File! : C:\Windows\qxzuwm.dat
Removed File! : C:\Windows\ywadm.dat
Removed File! : C:\Windows\oybzpp.dat
Removed File! : C:\Windows\gyteka.dat
Removed File! : C:\Windows\zzmsmk.dat
Removed File! : C:\Windows\rppeb.dat
Removed File! : C:\Windows\vbylt.dat
Removed File! : C:\Windows\jsyrg.dat
Removed File! : C:\Windows\dksylj.dat
Removed File! : C:\Windows\vlcent.dat
Removed File! : C:\Windows\uloui.dat
Removed File! : C:\Windows\vxnzly.dat
Removed File! : C:\Windows\nyfeni.dat
Removed File! : C:\Windows\svrbu.dat
Removed File! : C:\Windows\vxnzl.dat
Removed File! : C:\Windows\yruwu.dat
Removed File! : C:\Windows\wddbpe.dat
Removed File! : C:\Windows\wbliow.dat
Removed File! : C:\Windows\ocenqy.dat
Removed File! : C:\Windows\nmmaf.dat
Removed File! : C:\Windows\acsin.dat
Removed File! : C:\Windows\vorgm.dat
Removed File! : C:\Windows\System32\mlbhv.dat
Removed File! : C:\Windows\System32\odyqg.dat
Removed File! : C:\Windows\System32\yqvhk.dat
Removed File! : C:\Windows\System32\oynca.dat
Removed File! : C:\Windows\System32\wvyuq.dat
Removed File! : C:\Windows\System32\lmupn.dat
Removed File! : C:\Windows\System32\hzbsk.dat
Removed File! : C:\Windows\System32\hsouo.dat
Removed File! : C:\Windows\System32\hruwz.dat
Removed File! : C:\Windows\System32\gytek.dat
Removed File! : C:\Windows\System32\uikdl.dat
Removed File! : C:\Windows\System32\uagjm.dat
Removed File! : C:\Windows\System32\ypyih.dat
Removed File! : C:\Windows\System32\lrijj.dat
Removed File! : C:\Windows\System32\pteha.dat
Removed File! : C:\Windows\System32\avhrw.dat
Removed File! : C:\Windows\System32\dxutq.dat
Removed File! : C:\Windows\System32\vnamw.dat
Removed File! : C:\Windows\System32\bwwlj.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 20:25:10
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 21:28:41, 11/09/2005
+ Report-Checksum: AE0C6FED
+ Scan result:
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@adviva[2].txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\kris\Cookies\kris@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\kris\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.7:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.12:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.16:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.40:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.41:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.42:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.43:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.50:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.51:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.52:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.53:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.55:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.69:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.75:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.79:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.80:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.88:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.93:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.99:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.100:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.101:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.102:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.110:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.111:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.112:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.116:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.123:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.133:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.144:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.166:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.167:C:\Documents and Settings\kris\Application Data\Mozilla\Firefox\Profiles\4357pffl.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\lisa\Cookies\
[email protected][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057202.exe -> Trojan.Feat.2 : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057203.exe -> Trojan.Feat.2 : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057204.exe -> Trojan.Feat.2 : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057205.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057206.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057207.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057208.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057209.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057210.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057211.exe -> TrojanDropper.Delf.z : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057212.dll -> TrojanDownloader.Dyfuca.cn : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057213.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057214.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057215.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057216.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057217.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057218.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057219.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057220.exe -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057221.exe -> TrojanDownloader.Small.Go : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057222.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057223.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057224.exe -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057225.dll -> Adware.MidADle : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057226.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057227.exe -> Trojan.SecondThought.a : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057228.exe -> Backdoor.Ruledor.e : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057229.exe -> TrojanDownloader.Small.py : Cleaned with backup
C:\System Volume Information\_restore{44F382E6-E9C2-4AB1-890F-8663E95A49E1}\RP215\A0057230.exe -> Spyware.180Solutions : Cleaned with backup
::Report End
hows that looking now???
Matt