the following were not present
C:\WINDOWS\System32\cvqraus.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [mckkff] C:\WINDOWS\System32\cvqraus.exe r
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
c:\windows\nail.exe <— file
c:\windows\dinst.exe <— file
c:\windows\dsr.dll <— file
c:\windows\svcproc.exe <— file
c:\windows\system32\cvqraus.exe <— file
new HJT log
Logfile of HijackThis v1.99.1
Scan saved at 12:45:09 PM, on 9/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\CJH\Desktop\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo -
http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo -
http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) -
http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
ewido log
———————————————————
ewido security suite - Scan report
———————————————————
+ Created on: 12:33:15 PM, 9/14/2005
+ Report-Checksum: 840FB66C
+ Scan result:
HKLM\SOFTWARE\IEagent -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\143 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\206 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\339 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\348 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\387 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\675 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\757 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2 -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2\ppops -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2\ssites -> Spyware.Begin2Search : Cleaned with backup
[904] C:\WINDOWS\System32\gkfsse.exe -> Trojan.Agent.cp : Cleaned with backup
[1052] VM_012E0000 -> Adware.BetterInternet : Error during cleaning
:mozilla.27:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.52:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.69:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.70:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.71:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.72:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.74:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.91:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.92:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.93:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.106:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.121:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.122:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.137:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.148:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.153:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.154:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.156:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.159:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.161:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.162:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.164:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.165:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.166:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.167:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.168:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.169:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.172:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.173:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.174:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.175:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.176:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.178:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.197:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.198:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.204:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\[removed][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\[removed][2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\CJH\Desktop\HJT\backups\backup-20050913-222912-757.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\labpengs.tmp -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\Stb.exe -> TrojanDownloader.Agent.tf : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\thin-94-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\CMSystem\CMSystem.exe -> Spyware.CASClient : Cleaned with backup
C:\Program Files\CMSystem\plugin.dll -> Spyware.CASClient : Cleaned with backup
C:\Program Files\Netscape\Netscape 6\Plugins\npwthost.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\aigxgg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Buddy.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\offun.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\sbehpgm.exe -> TrojanDropper.Agent.tb : Cleaned with backup
C:\WINDOWS\system32\70tovmto.ini -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\gkfsse.exe -> Trojan.Pakes : Cleaned with backup
C:\WINDOWS\system32\in4bdlA.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\msdioo.exe -> Trojan.Small.i : Cleaned with backup
C:\WINDOWS\system32\msfaol.dll -> Spyware.ClientMan : Cleaned with backup
C:\WINDOWS\system32\msnimk.gif -> Spyware.Ipend : Cleaned with backup
C:\WINDOWS\system32\nsaC3C.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\nsvB89.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\redtrsha.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\wirelanb.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\System320nse12E0 -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\vdymzze.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\yxpwmjogek.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.18:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.32:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.33:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.40:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Linkbuddies : Cleaned with backup
:mozilla.41:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.42:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
F:\WINDOWS\Cookies\anyuser@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
G:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.RiskWare.Downloader.PopCap.a : Cleaned with backup
G:\Documents and Settings\Somer\Cookies\Somer@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
G:\Documents and Settings\Somer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-37b2f810-3c9511aa.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
G:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
I:\Program Files\1stpage\IScripts\Buttons\Six buttons from hell.izs -> Trojan.Loop : Cleaned with backup
J:\current c compaq\Program Files\Evrsoft\1st Page 2000\IScripts\Buttons\Six buttons from hell.izs -> Trojan.Loop : Cleaned with backup
::Report End