Some of the malware besides the VX2.Look2Me that I have removed are:
Trojan.Backdoor.Retro64
WebSearch Toolbar
icannnews
Bargain Buddy
AproposMedia
AvenueMedia.DyFuca
Trojan.Downloader.AdMSI
MediaMotor
I would appreciate any help you can give me to get my computer back to normal. I've spent hours working on this already and I am getting very frustrated
Here are my logs:
Logfile of HijackThis v1.99.1
Scan saved at 4:37:05 AM, on 10/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp WinStyler\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\rundll32.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis_v1.99.01.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.h...ario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...ario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...ario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.h...ario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = What would Jesus do in the same situation?
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\g0lmla311d.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp WinStyler\WinStylerThemeSvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:36:35 AM, 10/22/2005
+ Report-Checksum: 86FF4865
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PrevAdX.dll\\.Owner -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/PrevAdX.dll\\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-21-3647710881-1938064149-1086009230-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-21-3647710881-1938064149-1086009230-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-21-3647710881-1938064149-1086009230-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6CB-189F-421A-88CD-07CFE51CFF10} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
[1244] C:\WINDOWS\system32\mfg4dmod.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\cgi-bin\email2afriend.asp -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\starmacc.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\appfreeztips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\archtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\babetips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\bushtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\chiltips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\cinnmochtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\cinscaptip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\cooltips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\doubtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\fagiotip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\fidtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\fieldtip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\fraptips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\hotdogletips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\ihoptips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\jamocatips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\kfcslawtips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\lobstips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\mulligatip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\nabsoreotips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\naztips1.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\oceantips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\oreoshaktips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\paydaytips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\pbcuptips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\pitacaestips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\pottips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\shaketip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\sonichetip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\soupnaz2tips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\ssupremetips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\tbwenchtip.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\thinmintips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\recipes\tips\wallabytips.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend1.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend10.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend11.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend12.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend2.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend3.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend4.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend5.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend6.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend7.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend8.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\All Users\Documents\From Laptop\Website Design\My Webs\sleuth\legends\legend9.htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0089292.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0089293.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0089303.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090308.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090311.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090317.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090320.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090326.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090329.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090335.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090338.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090379.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP272\A0090386.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP273\A0091382.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP273\A0091391.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP273\A0091395.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP273\A0091397.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\azaq0ed5eh0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\e6020gdoe60c0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\g2220cfoef2c0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\h40q0ed5eh0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\izrop.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kvdusx.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\m0jula191d.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\m0rm0a91ed.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mccsubs.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mqxml3r.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\pxintui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\xasp1res.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__mfg4dmod.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\Cookies\compaq_owner@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\WINDOWS\Temp\Cookies\compaq_owner@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\compaq_owner@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
::Report End