Trevuren,
As you requested, I installed and ran Trojan Hunter and Ewido. They each found items to remove. The new HJT log and ewido.txt logs follow... Thanks again for your help.
Logfile of HijackThis v1.99.1
Scan saved at 2:57:13 PM, on 10/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijackthis\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://desktop.presa...&c=2C01&lc=0409R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.presar...&c=2C01&lc=0409R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.presar...&c=2C01&lc=0409O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1127768565711O17 - HKLM\System\CCS\Services\Tcpip\..\{01CF1E18-2084-4D34-9885-F4D62305D185}: NameServer = 85.255.113.124,85.255.112.15
O17 - HKLM\System\CCS\Services\Tcpip\..\{D31D2105-8233-45B9-A7BB-7C21852E98E1}: NameServer = 85.255.113.124,85.255.112.15
O17 - HKLM\System\CS1\Services\Tcpip\..\{01CF1E18-2084-4D34-9885-F4D62305D185}: NameServer = 85.255.113.124,85.255.112.15
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\COMPAQ\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 2:49:05 PM, 10/5/2005
+ Report-Checksum: 4D5241BF
+ Scan result:
HKLM\SOFTWARE\Classes\Interface\{08E05EED-5EE9-11D4-9CAF-00D0B76063FD}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{08E05EEF-5EE9-11D4-9CAF-00D0B76063FD}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C3E62835-DDF1-4242-9DD2-7C6C376197C5}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{E88A59EA-085C-44A5-A912-25F7FF7D2AD2}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{E88A59EB-085C-44A5-A912-25F7FF7D2AD2}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{E88A59EC-085C-44A5-A912-25F7FF7D2AD2}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FF825A39-251F-47AF-949F-E885C4EE4367}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FF825A3A-251F-47AF-949F-E885C4EE4367}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FF825A3B-251F-47AF-949F-E885C4EE4367}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FF825A3C-251F-47AF-949F-E885C4EE4367}\TypeLib\\ -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-21-2000478354-1957994488-1136801667-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
[204] VM_00D60000 -> TrojanDownloader.Agent.uj : Error during cleaning
[228] VM_00C50000 -> TrojanDownloader.Agent.uj : Error during cleaning
[740] VM_007B0000 -> TrojanDownloader.Agent.uj : Error during cleaning
C:\Program Files\SWiSHpix\ScreenSaver.scr -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Documents and Settings\default\My Documents\Quarantine\winupdate85612983[1].exe.tcf -> TrojanDropper.Small.ue : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@preferences[1].txt -> Spyware.Cookie.Preferences : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][4].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Epilot : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@findwhat[1].txt -> Spyware.Cookie.Findwhat : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@com[3].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@cj[1].txt -> Spyware.Cookie.Cj : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@com[5].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@adorigin[1].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@com[4].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlykjc5maoqydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyegcpceqaidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Cj : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkougajklpawdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4alc5abpasdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkyuhazagqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliondzgcoqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@cj[2].txt -> Spyware.Cookie.Cj : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@cj[3].txt -> Spyware.Cookie.Cj : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][3].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\default@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\default\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Elaine\Cookies\
[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP815\A0071071.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP815\A0071097.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP815\A0071077.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP815\A0071103.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP818\A0071187.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP818\A0071193.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071210.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071261.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071216.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071267.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071282.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071289.exe -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP820\A0071291.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070376.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070439.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070456.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070459.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070462.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070463.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070489.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070493.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070498.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070380.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070445.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070472.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP785\A0070502.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP788\A0070560.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP788\A0070564.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP812\A0070826.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP812\A0070856.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP812\A0070833.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP812\A0070863.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP813\A0070918.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP813\A0070986.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP813\A0070924.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP813\A0070992.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP814\A0071051.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP814\A0071057.exe.tcf -> Trojan.Small.fb : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP817\A0071143.exe -> TrojanDownloader.Agent.uj : Cleaned with backup
C:\System Volume Information\_restore{30C3E581-9422-4ED6-85E3-9BB93E6019AB}\RP817\A0071147.exe.tcf -> Trojan.Small.fb : Cleaned with backup
::Report End