Incident Status Location
Adware:adware/exact.searchbar Reported C:\Documents and Settings\Abc\Local Settings\Temp\blank.gif
Adware:adware/ist.istbar Reported C:\Documents and Settings\Abc\Local Settings\Temp\shortcuts.txt
Adware:adware/bookedspace Reported C:\WINDOWS\cfgmgr52.ini
Spyware:spyware/cydoor Reported C:\WINDOWS\cdmxtras
Adware:adware/powerscan Reported Windows Registry
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Cookies\abc@adrevolver[1].txt
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Cookies\abc@adrevolver[3].txt
Spyware:Cookie/Banner Reported C:\Documents and Settings\Abc\Cookies\abc@banner[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Cookies\abc@belnk[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Cookies\
[email protected][2].txt
Spyware:Cookie/Doubleclick Reported C:\Documents and Settings\Abc\Cookies\abc@doubleclick[1].txt
Spyware:Cookie/go Reported C:\Documents and Settings\Abc\Cookies\abc@go[2].txt
Spyware:Cookie/Hitbox Reported C:\Documents and Settings\Abc\Cookies\abc@hitbox[1].txt
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Abc\Cookies\abc@realmedia[1].txt
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Abc\Application Data\Mozilla\Firefox\Profiles\2afx8gez.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Abc\Application Data\Mozilla\Firefox\Profiles\2afx8gez.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Abc\Application Data\Mozilla\Firefox\Profiles\2afx8gez.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Abc\Application Data\Mozilla\Firefox\Profiles\2afx8gez.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Cookies\abc@adrevolver[1].txt
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Cookies\abc@adrevolver[3].txt
Spyware:Cookie/Banner Reported C:\Documents and Settings\Abc\Cookies\abc@banner[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Cookies\abc@belnk[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Cookies\
[email protected][2].txt
Spyware:Cookie/Doubleclick Reported C:\Documents and Settings\Abc\Cookies\abc@doubleclick[1].txt
Spyware:Cookie/go Reported C:\Documents and Settings\Abc\Cookies\abc@go[2].txt
Spyware:Cookie/Hitbox Reported C:\Documents and Settings\Abc\Cookies\abc@hitbox[1].txt
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Abc\Cookies\abc@realmedia[1].txt
Spyware:Cookie/Abcsearch Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@abcsearch[1].txt
Spyware:Cookie/Hbmediapro Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@adrevolver[1].txt
Spyware:Cookie/Adrevolver Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@adrevolver[2].txt
Spyware:Cookie/Apmebf Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@apmebf[2].txt
Spyware:Cookie/Ask Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@ask[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/Azjmp Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@azjmp[2].txt
Spyware:Cookie/Banner Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@banner[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@belnk[2].txt
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@bravenet[1].txt
Spyware:Cookie/Cgi-bin Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@cgi-bin[1].txt
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/go Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@go[1].txt
Spyware:Cookie/Com.com Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@maxserving[2].txt
Spyware:Cookie/OfferOptimizer Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@offeroptimizer[1].txt
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@realmedia[1].txt
Spyware:Cookie/Reliablestats Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/Zedo Reported C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@zedo[1].txt
Spyware:Cookie/Hypercount Reported C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq14.tmp
Virus:Trj/Multidropper.TY Reported C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq3B.tmp
Adware:Adware/WUpd Reported C:\Documents and Settings\cesar\Local Settings\Temporary Internet Files\Content.IE5\O0H2C05T\prompt[1].php
Adware:Adware/WUpd Reported C:\Documents and Settings\cesar\Local Settings\Temporary Internet Files\Content.IE5\WN3Z2C5P\count[1].htm
Spyware:Cookie/Ask Reported C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2037.txt
Adware:Adware/Transponder Reported C:\WINDOWS\system32\rrhvqlx.exe
Logfile of HijackThis v1.99.1
Scan saved at 8:29:29 PM, on 10/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.netO2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [InstaFinderK] C:\Program Files\INSTAFINK\InstaFinderK_inst.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\system32\LVCOMS.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.c...es/MsnInstC.cabO16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} -
http://www.pacimedia...ll/pcs_0025.exeO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www.snapfish....fishActivia.cabO16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) -
http://www.icannnews.../ST/ActiveX.ocxO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by20fd.bay20....es/MsnPUpld.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1103864666374O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} -
http://static.zangoc...e/bridge-c5.cabO16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) -
http://www.snapfish....pfishUpload.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
http://photos.yahoo....plorer1_9us.cabO20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:07:12 PM, 10/22/2005
+ Report-Checksum: F7D49A2E
+ Scan result:
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID\\ -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller.1 -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller.1\CLSID\\ -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0AC49246-419B-4EE0-8917-8818DAAD6A4E}\TypeLib\\ -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{03B800F9-2536-4441-8CDA-2A3E6D15B4F8} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{03B800F9-2536-4441-8CDA-2A3E6D15B4F8}\TypeLib\\ -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9}\TypeLib\\ -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD}\TypeLib\\ -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DFBCC1EB-B149-487E-80C1-CC1562021542} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DFBCC1EB-B149-487E-80C1-CC1562021542}\TypeLib\\ -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5}\TypeLib\\ -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44} -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5B6689B5-C2D4-4DC7-BFD1-24AC17E5FCDA} -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-725345543-1060284298-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99410CDE-6F16-42CE-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Abc\Application Data\Mozilla\Profiles\default\db90df5t.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Abc\Application Data\Mozilla\Profiles\default\db90df5t.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Abc\Application Data\Mozilla\Profiles\default\db90df5t.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Abc\Application Data\Mozilla\Profiles\default\db90df5t.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Abc\Cookies\abc@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Application Data\Wildtangent\Cdacache\00\00\07.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][3].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@adviva[1].txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\abc@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\Del27.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\ICD4.tmp\MediaGatewayX.dll -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\MediaGateway.exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temp\res28.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Abc\Local Settings\Temporary Internet Files\Content.IE5\QISKUV5X\SAcc.prod.v1112.05oct2005.exe[1].3ba72c661930662f21ed89952e0fec96 -> Spyware.SurfAccuracy : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq12.tmp -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16.tmp -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq17.tmp -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq18.tmp -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq1A.tmp -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq1C.tmp -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq6.tmp -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppqB.tmp -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppqC.tmp -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppqD.tmp -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppqE.tmp -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppqF.tmp -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Program Files\Norton AntiVirus\Quarantine\Portal\45F02B59.exe -> Trojan.Crypt.e : Cleaned with backup
C:\Program Files\WinFixer 2005 -> Spyware.WinFixer : Cleaned with backup
C:\RECYCLER\NPROTECT\00182665.DLL -> TrojanDownloader.IstBar : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2033.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2036.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2038.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2043.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2045.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2046.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2047.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2056.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2058.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\RECYCLER\S-1-5-21-725345543-1060284298-1202660629-1003\Dc2059.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ActiveX.ocx -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\system32\APD123.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\system32\donetlib.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\drivers\df_kmd.sys -> Trojan.Rootkit.Agent.af : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ithlpapi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\izagr5.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\qhujko.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Temp\b.com -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4HEVK5IV\!update-2124[1].0000 -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\Temp\upd209.exe -> Spyware.Look2Me : Cleaned with backup
::Report End
IS THAT WHAT YOU WERE LOOKING FOR?.. ITS SO CONFUSING :'o