This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple popups possibly persist

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a friend's machine.

Had previously used add/remove programs to unistall obvious problems

Updated definitions & ran Spysweeper 3.2
Then updated to Spysweeper 4.0.3 and updated definitions & ran again
Both found problems
Ran Spybot S+D with fresh definitions, found 67 items
Ran CW Shredder, nothing found

This is a Win XP Home machine with Firefox default browser
Lots of popups - all coming in IE, of course
Also, can't switch users (click is ignored) but can logout and login from main user screen

After the sweeps it appears to be better, but wasn't sure. Here's HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:51:18 PM, on 07/05/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\America Online 7.0a\aoltray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\HJT\HijackThis_199_1.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - _{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [C:\WINDOWS\wswe.exe] C:\WINDOWS\wswe.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0a\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\My Downloads\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1103906323140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


rickg32
Hi Rick, Welcome to TomCoyote and sorry about the wait. Nice of you to help a friend :) I do see some issues, and will make my suggestions in a moment, but first:
This item: O4 - HKLM\..\Run: [C:\WINDOWS\wswe.exe] C:\WINDOWS\wswe.exe does not identify and I think it is bad. It is not running from Programs, so must be originating from Temp or Prefetch? Unless you know what it is, it should be removed. If you need more information before you remove it, you can get that here: http://virusscan.jotti.org/

This product: O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab does not yet appear on the list we use to ID rouge products here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm but take a look at these, I believe you have a bad product onboard and I will schedule removal.
http://www.pcreview.co.uk/startup/SpySpott…/SpySpotter.php
http://www.spyware-reviews.com/rogue-spyware.php

I suggest you do this:

1) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions on the download page and please do not run it until I ask you to.

2) You said you ran Spybot, use this link to get Ad-aware onboard and make sure both are updated and configured properly. You can run them both again if you wish: http://tomcoyote.org/aawsb.php

3) Please download Ewido Security Suite
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • When it asks if you want to remove the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose remove and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

**some items may be gone after Ewido, just don't miss any**

4) SpySweeper may block the HJT fix, turn it off until you are done.

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - _{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
O4 - HKLM\..\Run: [C:\WINDOWS\wswe.exe] C:\WINDOWS\wswe.exe
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab

Close all programs but HJT and all browser windows, then click on "Fix Checked"

6) SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\wswe.exe >>> file

Locate C:\Windows\Prefetch folder and open it. Delete the contents of the folder (NOT THE FOLDER) if there are many choose Edit then Select all then Delete. You may not be able to remove them all, don't be concerned unless any have the name of the items we need to remove. Here is some information about the Prefetch for you:
http://www.windowsnetworking.com/articles_…refetch-XP.html

7) Run CCleaner but do not use the registry cleaner unless you Backup the registry first as prompted. Then restart the computer and post a new HJT log along with the Ewido scan results in this same thread along with any feedback you have. Let us know how you are running.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Well, pskelley

after two hours … hope I can still read my notes.

Adaware SE 1.06 found 186 problems … fixed
Reran Spybot S+D 1.4 … only found one … Wild Tangent .. fixed

Did an add/REMOVE program on Spy Spotter … said there was an unused file robj1.dll which I did not delete

Ewido 3.5 procedures followed …300+ probs found … log follows comments
The following messages (approx) from Ewido during remove phase

….mindi\Local Settings\Temp\ICD1.tmp/IAientee.dll in archive … deleted
…._restore…. exdl.exe … didn't delete as in restore point
…. system32\biU.exe./bi.dll …. didn't delete as in system32
…. system32\IAientee.dll/bi.dll …. deleted as matched first one
…. system32\nostalgia.dll/MSView.dll …. deleted on gut feel about name

HJT
The R1 entry wasn't there

Went to delete wswe.exe … wasn't there

Ran CCleaner
cleared the Prefetch directory

Here are the logs (no noticeable change in behavior, but the R0 entry didn't go away):

Logfile of HijackThis v1.99.1
Scan saved at 9:00:25 PM, on 07/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\WINDOWS\System32\RUNDLL32.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\America Online 7.0a\aoltray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\HJT\HijackThis_199_1.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0a\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1103906323140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Ewido

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 8:45:01 PM, 07/11/2005
+ Report-Checksum: 1E20AA89

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{421A63BA-4632-43E0-A942-3B4AB645BE51} -> Spyware.InternetWasher : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\h8bgitx1.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Alan\Local Settings\Temp\first.exe -> Spyware.F1Organizer : Cleaned with backup
C:\Documents and Settings\Alan\Local Settings\Temp\omnigate.exe -> Spyware.Omnigate : Cleaned with backup
C:\Documents and Settings\Alan\Local Settings\Temp\optimize.exe -> TrojanDownloader.Dyfuca.ak : Cleaned with backup
C:\Documents and Settings\Alan\Local Settings\Temp\v2.dll -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Alan\Local Settings\Temporary Internet Files\Content.IE5\R52HEPUT\pi[1].exe -> TrojanDownloader.Small.afq : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Emily\Application Data\Mozilla\Firefox\Profiles\eiennm0f.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Emily\Cookies\emily@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Emily\Local Settings\Temp\FreeBuddyIcons.exe -> TrojanDropper.Agent.bc : Cleaned with backup
C:\Documents and Settings\Emily\Local Settings\Temp\VT09.exe -> TrojanDownloader.Lookme.e : Cleaned with backup
C:\Documents and Settings\Emily\Local Settings\Temp\ysbinstall_1000290.exe -> TrojanDownloader.IstBar.er : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Specificpop : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.399:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.400:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.401:C:\Documents and Settings\Evelyn\Application Data\Mozilla\Firefox\Profiles\n9yhhn3f.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Evelyn\Cookies\evelyn@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.211:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.212:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.t
Hello Rick, Sorry about how long it took to run Ewido, last time I ran it on my computer it took 37 minutes. I do believe the Ewido log was cut off so I can't see if there was much more but if you take a look at that log you will see there was a lot of junk on the computer. By far the items were cookies stored in the Firefox browser. You can delete those cookies by opening Firefox then click on Tools, Options then Privacy tab. Then Clear cookies, I have cookies turned off on my Firefox browser but I use IE most of the time. If your friend is going to use Firefox, you should show them how to clear these cookies. I also need to see the balance of the log so I can see if there was anything there Ewido could not remove. You said this:

Here are the logs (no noticeable change in behavior, but the R0 entry didn't go away):

I need more information about what is occuring, because I do not see it in either log. I can tell you that this item: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = is just clutter and sometimes they are hard to remove. It is not doing any harm, but if you are sure Spysweeper was turned off then if you wish to remove the item, try to use HJT to do it in safe mode:
http://www.bleepingcomputer.com/forums/tutorial61.html

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Miscommunication … ewido took only a few minutes. Installling & configuring AdAware, and running Adaware & Spybot S+D took the most time. But I'd figured on two hours and it was pretty close. I would think running CCleaner earlier would reduce time by cleaning out lots of temps that were scanned … your comments? Fortunately the ewido log was just a bad cut & paste, so I don't have to go back for it. Here is the bottom part of that log: :mozilla.214:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.215:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.223:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.228:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.229:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.239:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.256:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.264:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.265:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.266:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.267:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.282:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.283:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.284:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.326:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.333:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.334:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.383:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.384:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.385:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.386:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.387:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.388:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.406:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.408:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.409:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.416:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.449:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.450:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.451:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.452:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.474:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.527:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup :mozilla.529:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup :mozilla.530:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup :mozilla.567:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup :mozilla.572:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.574:C:\Documents and Settings\Mindi\Application Data\Mozilla\Firefox\Profiles\bj5ielzm.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Documents and Settings\Mindi\Application Data\wjhuhbbw.exe -> TrojanDownloader.Swizzor.bd : Cleaned with backup C:\Documents and Settings\Mindi\Cookies\mindi@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup C:\Documents and Settings\Mindi\Local Settings\Temp\bundlersi.exe -> TrojanDownloader.IstBar : Cleaned with backup C:\Documents and Settings\Mindi\Local Settings\Temp\ICD1.tmp\IAientee.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup C:\Documents and Settings\Mindi\Local Settings\Temp\ICD1.tmp\IAientee.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup C:\Documents and Settings\Mindi\Local Settings\Temp\uninstall.exe -> Spyware.EliteBar : Cleaned with backup C:\EliteToolBar version 60.dll -> Spyware.EliteBar : Cleaned with backup C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup C:\RECYCLER\S-1-5-21-1964228415-2860127378-1869523861-1008\Dc125.com -> Trojan.Crypt.d : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP590\A0670131.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0680475.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP602\A0684495.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP603\A0684895.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP607\A0689918.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP610\A0692072.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP612\A0696070.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP616\A0700144.exe -> Adware.SaveNow : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP616\A0700196.dll -> Spyware.WildTangent : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP616\A0700211.dll -> Spyware.WildTangent : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700434.exe -> Spyware.CaptainCode : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700435.exe -> TrojanDownloader.QDown.m : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700439.dll -> Adware.eZula : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700441.exe -> Spyware.WinShow : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700448.exe -> TrojanDropper.SurfSide.a : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700455.exe -> Spyware.MediaMotor : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700456.exe -> Spyware.MediaMotor : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700458.ocx -> TrojanDownloader.VB.ez : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700460.exe -> Trojan.QuickBrowser : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700462.exe -> TrojanDownloader.IstBar.gg : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700464.exe -> Trojan.Small.i : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700465.exe -> Spyware.F1Organizer : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700467.exe -> TrojanDownloader.Small.gl : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700468.exe -> Spyware.Web3000 : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700469.exe -> Adware.eZula : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700478.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700479.exe -> TrojanDownloader.Small.adu : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700494.dll -> Spyware.WinAD : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/bbchk.exe -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/msexreg.exe -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP617\A0700509.vxd/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy : Error during cleaning C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0701852.exe -> Spyware.DatingCity : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0750256.exe -> Spyware.BargainBuddy : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0750257.exe -> Trojan.TalkStocks.a : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0750263.com -> Trojan.Crypt.d : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0752278.dll -> Spyware.EliteBar : Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP660\A0752279.dll -> Spyware.EliteBar : Cleaned with backup C:\temp\WinCtlAdInstPack.exe -> Spyware.WinAD : Cleaned with backup C:\WINDOWS\chzmslbv.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\jyggtbhc.dll -> TrojanDownloader.Lemmy.u : Cleaned with backup C:\WINDOWS\NDNuninstall5_20.exe -> Spyware.NewDotNet : Cleaned with backup C:\WINDOWS\NDNuninstall5_64.exe -> Spyware.NewDotNet : Cleaned with backup C:\WINDOWS\NDNuninstall6_10.exe -> Spyware.NewDotNet : Cleaned with backup C:\WINDOWS\pi1.exe -> TrojanDownloader.Small.afq : Cleaned with backup C:\WINDOWS\sjpvjihe.dll -> TrojanDownloader.Skoob.c : Cleaned with backup C:\WINDOWS\SYSTEM32\a5wu37rd.exe -> Spyware.F1Organizer : Cleaned with backup C:\WINDOWS\SYSTEM32\Agent.dll -> Adware.SAHA : Cleaned with backup C:\WINDOWS\SYSTEM32\biU.exe/bi.dll -> Trojan.Bispy.A : Error during cleaning C:\WINDOWS\SYSTEM32\biU.exe/preInsBI.exe -> Spyware.BiSpy : Error during cleaning C:\WINDOWS\SYSTEM32\BO2202031216.dll -> Spyware.BargainBuddy : Cleaned with backup C:\WINDOWS\SYSTEM32\bUS.dll -> Adware.eZula : Cleaned with backup C:\WINDOWS\SYSTEM32\c17b6s.dll -> Adware.eZula : Cleaned with backup C:\WINDOWS\SYSTEM32\ctbv2.dll -> Adware.SAHA : Cleaned with backup C:\WINDOWS\SYSTEM32\elitealp32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteaxn32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitebdi32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitebvx32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitecar32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitecik32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitecla32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedfd32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedfm32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedii32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedno32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitednv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedrb32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedze32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitedzm32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteeew32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteegv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteexk32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitefaa32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitefbr32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitefvy32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitegdp32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitegdy32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitegov32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitegss32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitehkg32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteift32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteiun32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteizj32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitejwd32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitekeu32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitekmj32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitekpi32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitekpz32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitektl32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitelcw32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitemuo32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitence32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitennt32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitenpn32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitenua32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitenzy32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteogh32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteohy32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteoke32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitepmm32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitepmz32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitepys32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliterdj32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliterfi32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitergp32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliterhw32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliterjo32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitersv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitesop32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitesul32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteswb32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitetpd32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteuej32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteues32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteuwg32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitevbe32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitevbs32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitevlt32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitevpz32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitewoe32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitewoh32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitexdh32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitexie32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitexlp32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitexwy32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\eliteyfd32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitezeh32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitezez32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitezgx32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\elitezyv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\SYSTEM32\first.exe -> Spyware.F1Organizer : Cleaned with backup C:\WINDOWS\SYSTEM32\IAientee.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup C:\WINDOWS\SYSTEM32\IAientee.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup C:\WINDOWS\SYSTEM32\mbbi8016.dll -> Spyware.BargainBuddy : Cleaned with backup C:\WINDOWS\SYSTEM32\NLNP13.dll -> Spyware.IGetNet : Cleaned with backup C:\WINDOWS\SYSTEM32\NLNP131.dll -> Spyware.IGetNet : Cleaned with backup C:\WINDOWS\SYSTEM32\nostalgia.dll/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup C:\WINDOWS\SYSTEM32\nostalgia.dll/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup C:\WINDOWS\SYSTEM32\SHAgent.dll -> Adware.SAHA : Cleaned with backup C:\WINDOWS\SYSTEM32\SHAgentNew.dll -> Adware.SAHA : Cleaned with backup ::Report End Next time I'll configure Firefox to delete all cookies on exit. Can't do anything else until tonight (we're same time zone at least!) rick
Hi Rick, Thanks for the additional information, and yes Ad-aware and Spybot do take a while when you run the complete system scan. These are two good tools for your friend, but they do not block anything (untill you activate TeaTimer in Spybot) they just remove it if it gets on. We can discuss some great free tools for blocking the junk once we have you running properly.

I would think running CCleaner earlier would reduce time by cleaning out lots of temps that were scanned … your comments?

CCleaner is one of the best utility tools I have found and indeed if it is used properly it will do a heck of a job for you…but I took a look and I do not think it cleans Firefox, suppose you will have to do that manually. I also suggest using the registry cleaner but only after you back it up. I never make any changes in the registry without doing this. Here is a tutorial one of the folks set up:
To use it:
Download CCleaner from http://www.ccleaner.com/ and install.
Open CCleaner.
Place a check by everything in the Applications tab.
Place a check by Internet Explorer, Windows explorer, and System in the Windows tab.
Hit the button that says Run CCleaner
Reboot to remove index.dat files.
CCleaner also has some other useful features:
Cookies: In CCleaner, you can customize which cookies to delete and which to keep, so you won't lose valuble logon information. To do so, open CCleaner, then go to Options>Cookies. Select the name of a website you logon to often (For example, forums.tomcoyote.org). Then, click the '–>' button so it's in the 'Cookies to keep' list. Repeat this for any other cookie you wish to keep. To place a cookie back on the 'Cookies to Remove' list, simply select the cookie and hit the '<–' button.
Uninstall manager: It's a tool to let you uninstall programs, and rename and delete uninstall entries.
It also has a forum here: http://forum.ccleaner.com/
Check for updates weekly, as new versions are released periodically

A look at the Ewido log shows that the computer was fairly infected. I would appreciate a new HJT log anytime you post so I can keep an eye on it. What I would like you to do is get rid of those cookies in Firefox and then also I would like to clean out the System Restore files like this:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
Here are also step by step instructions:
MANUAL INSTRUCTIONS FOR SYSTEM RESTORE
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

My problem is that I do not see any reason for issues, and need as much information about any you are having. If something is hiding from us, the more I know about what they are doing will help the fiure out how to look for them. Prior to starting a search, I would appreciate it if you would do this. Since our scans removed so much junk, I would like to give them a chance at anything left in Safe Mode:
If you would run at least Ewido (after you clean out System Restore and Firefox cookies) as I am looking for a clean Ewido log, and it would be a good thing to run Ad-aware and Spybot also. In diagnostic mode these programs will have a better chance at cleaning anything that is left.
I think I see MSNIM on the computer, if you want to use it for realtime communication since we are in the same time zone, let me know. Once you have completed these scans in Safe Mode, post a new Ewido and HJT log and surf a bit first to see if perhaps we have eliminated the issue. Thanks…Phil
Phil,

Ran out of time after 1-1/2 hours, but got most of it done

1) cleared cookies and cache from Firefox for each of 4 users. Reset cache sizes 50mb ->5mb
2) cleaned System Restore files as per instructions
3) backed up & cleaned registry with CCleaner

Went into Safe Mode
4) Ran ewido … picked up 2 problems both in ….system32, one a trojan, and the other system32\biU.exe./bi.dll which I hadn't deleted last time but did this time.

Forgot to click the Save Log button … so reran ewido just for System … 45 mins for 2 runs … short log lol

5) Ran HJT in safe mode and saved log

The system appears to be functioning okay now …. but it appeared to be before we started and removed a number of problem issues.

The only remaining problem is the inability to switch users … which is probably not malware related

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 8:55:50 PM, 7/12/2005
+ Report-Checksum: CAB93AD9

+ Scan result:

No infected objects found.


::Report End

——-
Logfile of HijackThis v1.99.1
Scan saved at 8:56:49 PM, on 7/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\HJT\HijackThis_199_1.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0a\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1103906323140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Don't normally use MSNIM, but willing to turn it on.

rick
It's a real friend that will do all of this work on somone else's computer :)

The only remaining problem is the inability to switch users … which is probably not malware related

What are you talking about here? WindowsXp users? Now that's what I call a "great" Ewido Scan report

The system appears to be functioning okay now …. but it appeared to be before we started and removed a number of problem issues.

Won't be necessary about MSNIM since it seems we have no complex removal to perform.
Looks like you were still in safe mode, if you would allow me one more HJT log in normal mode as I can't see all running processes in safe mode, then I can turn you loose. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

If you are refering to the inability to switch Windows Xp users, look at this information:

http://help.lockergnome.com/index.php?showtopic=35569
http://www.theeldergeek.com/HT0_005.htm
http://www.winsupersite.com/reviews/windowsxp.asp

Not really my forte', but perhaps something there will help.

Thanks…Phil
Phil,

I've posted below the (final?) HJT log.
The other two were useless, but the lockergnome link was a hit for resolving my XP User switching problem …. I had turned off what I thought were non-essential services … appears Terminal Service is required for user switching … go figure.

I'd like to say I've learned a lot about resolving malware problems from your comments. I like your approach. To me, that's as important as fixing this machine… I signed up for classroom training a couple weeks ago, but haven't heard back yet.

Thanks,
Rick

Logfile of HijackThis v1.99.1
Scan saved at 7:46:43 PM, on 07/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\America Online 7.0a\aoltray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis_199_1.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0a\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1103906323140
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi Rick, Great to hear you are considering Classroom. I am surprised you have not heard anything. Why don't you try them again in case your information did not reach them. Happens with notifications sometimes. There are several other free schools available also if you wish information let me know. I know it is a lot when you first start, if there is anything I can do.
I actually purchased my first computer about six years ago and became interested first in general troubleshooting. I met the owner of one of the schools I mentioned above when he was removing malware at Dell forum, and he convinced me to look into malware removal and pointed me towards TomCoyote. I'm about two years or so into this and I have found that they seem to be writing the stuff faster than I can learn how to remove it, so we can always use more help.

This final log looks fine, it was good working with you. I'm off on a holiday soon but will leave the thread for a couple of days in case any questions come up.
Safe Surfing…Phil
Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI