Thanks for your help.
Here is what I have after following your suggestions.
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:54:17 PM, 10/22/2005
+ Report-Checksum: D778BB1B
+ Scan result:
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MulDist.ocx\\.Owner -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MulDist.ocx\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/mfc42.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/msvcrt.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/olepro32.dll\\{FC87A650-207D-4392-A6A1-82ADBC56FA64} -> Spyware.MoneyTree : Cleaned with backup
HKU\S-1-5-21-2594536663-1226255715-1664017535-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\ar3.jar-71002e85-28b91c47.zip/Gummy.class -> Trojan.Java.Femad : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\Counters.jar-64e31c12-61251236.zip/Counter.class -> Trojan.Femad : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\Counters.jar-64e31c12-61251236.zip/VerifierBug.class -> Trojan.Java.Femad : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\Counters.jar-64e31c12-61251236.zip/Gummy.class -> Trojan.Java.Femad : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\Counters.jar-64e31c12-61251236.zip/Xeyond.class -> Trojan.Java.Femad : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\Counters.jar-64e31c12-61251236.zip/web.exe -> TrojanDropper.Small.ja : Cleaned with backup
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\loaderfox.jar-805f85b-206e1b72.zip/Counter.class -> Trojan.ClassLoader.h : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Sidefind : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\bb.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Del2C.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Del4C.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Del80.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\iinstall.exe -> TrojanDownloader.IstBar.li : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\ileihe.exe -> Backdoor.Agobot : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\nyesekr.exe -> Backdoor.Agobot : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\optimize.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\rayykcv.exe -> Backdoor.Agobot : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\res2D.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\res3.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\sidefind.exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\testt.exe -> Backdoor.Agobot : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\uninstall.exe -> TrojanDownloader.IstBar.gi : Cleaned with backup
C:\Program Files\SpyHunter\Backup\bbchk.exe.bak -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@247realmedia[1].txt.bak -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@addynamix[1].txt.bak -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.X10 : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.X10 : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@adtech[2].txt.bak -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@advertising[1].txt.bak -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@advertising[2].txt.bak -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@atdmt[1].txt.bak -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@atdmt[2].txt.bak -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@bfast[1].txt.bak -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@bfast[2].txt.bak -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@bluestreak[1].txt.bak -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@bluestreak[2].txt.bak -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@casalemedia[1].txt.bak -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@casalemedia[2].txt.bak -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@centrport[1].txt.bak -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@centrport[2].txt.bak -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@commission-junction[1].txt.bak -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@doubleclick[1].txt.bak -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@fastclick[1].txt.bak -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@fastclick[2].txt.bak -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@gator[1].txt.bak -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@hitbox[1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@hitbox[2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@linksynergy[1].txt.bak -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@linksynergy[2].txt.bak -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@mediaplex[1].txt.bak -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@mediaplex[2].txt.bak -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@offshoreclicks[1].txt.bak -> Spyware.Cookie.Offshoreclicks : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@qksrv[1].txt.bak -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@qksrv[2].txt.bak -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@revenue[1].txt.bak -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@sexlist[1].txt.bak -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@sexlist[2].txt.bak -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@sextracker[1].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@sextracker[2].txt.bak -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@specificpop[1].txt.bak -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@specificpop[2].txt.bak -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@spylog[1].txt.bak -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@targetnet[1].txt.bak -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@targetnet[2].txt.bak -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@trafficmp[1].txt.bak -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@trafficmp[2].txt.bak -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][2].txt.bak -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@valueclick[1].txt.bak -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@valueclick[2].txt.bak -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@valueclick[3].txt.bak -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@weborama[2].txt.bak -> Spyware.Cookie.Weborama : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@xxxcounter[1].txt.bak -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Program Files\SpyHunter\Backup\owner@xxxcounter[2].txt.bak -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Program Files\SpyHunter\Backup\
[email protected][1].txt.bak -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : Cleaned with backup
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : Cleaned with backup
C:\temp\ZCWEDowST3.exe -> TrojanDropper.Agent.rs : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0826NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.10\UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.12\UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.9\UWFX5NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0826NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\YSBactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\HJ4MG4LI\141.154.11[1].gif -> TrojanProxy.Bobax.a : Cleaned with backup
C:\WINDOWS\system32\f0r0r\dorod.exe -> Backdoor.Hacdef : Cleaned with backup
C:\WINDOWS\system32\f0r0r\niamx -> Worm.Randon.aa : Cleaned with backup
C:\WINDOWS\system32\f0r0r\ppi.exe -> Backdoor.MotivFTP.12 : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe2305.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe37AA.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe42FF.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe43E.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe4A9D.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe52DC.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe538B.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe5AC1.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe6BA.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxe7BD.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxeB36.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxeC2.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\sxeF83.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\f0r0r\van32.exe -> Trojan.Hiddenrun : Cleaned with backup
C:\WINDOWS\system32\f0r0r\wexp.exe -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\dorod.exe -> Backdoor.Hacdef : Cleaned with backup
C:\WINDOWS\system32\wms\sxe1003.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe209F.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe23DA.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe2D5E.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe3D4A.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe3DF5.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe3DFE.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe3F0.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe454B.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe4F5.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe4FA3.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe6A35.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxe6AF8.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxeEB9.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\sxeECE.tmp -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
C:\WINDOWS\system32\wms\wexp.exe -> Not-A-Virus.Exploit.RPCLsa.01.c : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 11:21:38 PM, on 10/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\hijackthis.exe\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://us9.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us9.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://cgi.verizon.n....5&bm=ho_searchR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.newburypo...ma.us/bresnahanR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Verizon Online Dialer.lnk = C:\Program Files\Common Files\Verizon Online\ConnMgr\Verizon Online.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1123276690942O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1128870896906O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://207.127.153.7...sCamControl.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{FA026F7E-799C-4520-BCD9-D3F90983C407}: NameServer = 151.202.0.85 151.203.0.85
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
Thank you very much indeed for your help.