This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ugly's Hijack This Log file

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my log file, please help me, thanks.

Logfile of HijackThis v1.99.1
Scan saved at 8:16:59 PM, on 9/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\System32\umonit.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
c:\windows\system32\win\palsp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
c:\windows\system32\word\palsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\etb\pokapoka69.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Uglywombat2004\Desktop\Nick's Stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us8l.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dnaads.com/servlet/ajrotator/128447…L?zone=enternet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [stratas] lockx.exe
O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\\etb\pokapoka67.exe
O4 - HKLM\..\Run: [Boarddata] c:\windows\system32\win\repcale.exe c:\windows\system32\win\palsp.exe
O4 - HKLM\..\Run: [System service68] C:\WINDOWS\\etb\pokapoka68.exe
O4 - HKLM\..\Run: [Boleta] c:\windows\system32\word\repcale.exe c:\windows\system32\word\palsp.exe
O4 - HKLM\..\Run: [System service69] C:\WINDOWS\etb\pokapoka69.exe
O4 - HKLM\..\RunServices: [stratas] lockx.exe
O4 - HKCU\..\Run: [stratas] lockx.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: Multi - C:\Program Files\Stardock\ThinkDesk\Multiplicity\MultiWin32.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Stardock Multiplicity (Multiplicity) - Unknown owner - C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
Greetings and welcome to TomCoyote.org!

Click here to download Ewido security suite - it is a trial version of the program.
  • Install Ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch Ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.

After the definitions have been updated, close Ewido.

Do NOT run a scan yet.

Reboot in "safe" mode.

Now, run Ewido, then:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folder's or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report.txt file to your desktop.
Now close Ewido security suite.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O4 - HKLM\..\Run: [stratas] lockx.exe

O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe

O4 - HKLM\..\Run: [System service67] C:\WINDOWS\\etb\pokapoka67.exe

O4 - HKLM\..\Run: [Boarddata] c:\windows\system32\win\repcale.exe c:\windows\system32\win\palsp.exe

O4 - HKLM\..\Run: [System service68] C:\WINDOWS\\etb\pokapoka68.exe

O4 - HKLM\..\Run: [Boleta] c:\windows\system32\word\repcale.exe c:\windows\system32\word\palsp.exe

O4 - HKLM\..\Run: [System service69] C:\WINDOWS\etb\pokapoka69.exe

O4 - HKLM\..\RunServices: [stratas] lockx.exe

O4 - HKCU\..\Run: [stratas] lockx.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\etb <— FOLDER

c:\windows\system32\win\palsp.exe <— file

c:\windows\system32\win\repcale.exe <— file

c:\windows\system32\word\palsp.exe <— file

c:\windows\system32\word\repcale.exe <— file

c:\windows\system32\lockx.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot and "copy/paste" a new Hijack This! log file, and the report.txt file from the Ewido scan, into this thread. :)
Hijack This Log

Logfile of HijackThis v1.99.1
Scan saved at 2:22:45 AM, on 9/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\System32\umonit.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Uglywombat2004\Desktop\Nick's Stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us8l.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Stardock Multiplicity (Multiplicity) - Unknown owner - C:\PROGRA~1\Stardock\THINKD~1\MULTIP~1\MULTIS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe


Ewido

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on:  2:12:42 AM, 9/24/2005
+ Report-Checksum:  DB7649D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Uglywombat2004\Application Data\Mozilla\Firefox\Profiles\z9enn35c.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\astr.exe -> TrojanDownloader.VB.na : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\uglywombat2004@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\uglywombat2004@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\uglywombat2004@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\uglywombat2004@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Cookies\uglywombat2004@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\dudde.exe -> TrojanDropper.Agent.mf : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Local Settings\Temp\Cookies\uglywombat2004@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\Local Settings\Temp\Cookies\[removed][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Uglywombat2004\msdirectx.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\Program Files\AlertSpy\SpyWares\spydb.exe -> Spyware.AlexaBar : Cleaned with backup
C:\Program Files\AlertSpy\uninst.exe -> Spyware.AlexaBar : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup


::Report End


BTW: I did everyhting in saf emode, except the Hijack This log file that i posted here, it seems to have disappeared, but i dont knwo for sure, it kept making my computer go back to its default settigns of everything. And it might still eb that way, ill have to restart it to chekc it out.
Looks good!!!

How's it running? :unsure:

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Everything is running well except for one thing. I watch anime and stuff on my comp, and I've ben able to watch episodes before on winamp, but now some of the video doesn't show up, just audio. Its not that big of a problem because I can just play them in VLC player, but I prefer winamp, any ideas? Also, the IESPYAD thng wont work for me because I don't have IE on my comp, I removed it. I use firefox, its better.
:scratch: Winamp isn't anywhere in this post until you mentioned it…. The only thing I could think of would be to uninstall it, reboot, then re-install it…. Even then, I cannot guarantee that would work….
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI