Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Hijack This Log


  • This topic is locked This topic is locked
12 replies to this topic

#1 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 23 November 2005 - 08:12 PM

Could you evaluate the log file c+p below, many thanks.

James Edge jedge@cfl.rr.com

Logfile of HijackThis v1.99.0
Scan saved at 9:08:11 PM, on 11/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Monster\Hub.exe
C:\WINDOWS\system32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Documents and Settings\ForeverProfit$\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll (file missing)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: (no name) - {E606052C-C26E-4A9D-835B-BABA8BA9F1F9} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SkySportsCluster] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monster Launcher.lnk = C:\Program Files\Monster\Hub.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Add Content To YMMSS Reader - res://C:\Program Files\YMMSS Reader\Tristana.exe/AddContent.js
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll (file missing)
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {04110BC2-B8B9-4CDD-8923-8C7C90F8B6A0} - http://monsterclient...20Installer.cab
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.side...00719/sb028.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia...ll/pcs_0025.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1104015628518
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1124291887173
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...560/mcfscan.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: HP Configuration Interface Service - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: McAfee WSC Integration - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Webroot Spy Sweeper Engine - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Advertisements

Register to Remove


#2 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 23 November 2005 - 09:09 PM

Hi and welcome to the forum. :D

Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeek...7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Step # 4

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

You need an updated version of Hijackthis which you can get from HERE.

#3 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 24 November 2005 - 08:08 AM

Hi there,

thanks for sending me the instructions for safe removal and doing the logs for Ewido and Hijack this. I have c+p the logs from both applicationsbelow, again thank you for all your help. If there is something showing up from the logs could you let me know my next step.

Cheers James

Hijack Log.

Logfile of HijackThis v1.99.1
Scan saved at 9:01:07 AM, on 11/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Monster\Hub.exe
C:\WINDOWS\wanmpsvc.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\AM Browser\AM Browser.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\ForeverProfit$\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: (no name) - {E606052C-C26E-4A9D-835B-BABA8BA9F1F9} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SkySportsCluster] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monster Launcher.lnk = C:\Program Files\Monster\Hub.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Add Content To YMMSS Reader - res://C:\Program Files\YMMSS Reader\Tristana.exe/AddContent.js
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll (file missing)
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {04110BC2-B8B9-4CDD-8923-8C7C90F8B6A0} - http://monsterclient...20Installer.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.side...00719/sb028.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia...ll/pcs_0025.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1104015628518
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1124291887173
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...560/mcfscan.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Ewido Log.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:39:16 AM, 11/24/2005
+ Report-Checksum: E5296E55

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6} -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D714A94F-123A-45CC-8F03-040BCAF82AD6} -> Spyware.SideStep : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\0\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\0\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\0\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\0\Controls\2 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\1\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\10 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\10\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\10\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\10\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\11 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\11\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\11\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\11\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\11\Controls\2 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\2 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\2\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\2\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\2\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\2\Controls\2 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\3 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\3\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\3\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\3\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\4 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\4\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\4\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\4\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\5 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\5\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\5\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\5\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\6 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\6\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\6\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\6\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\7 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\7\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\7\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\7\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\7\Controls\2 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\8 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\8\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\8\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\8\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\9 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\9\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\9\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\9\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\A -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\A\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\B -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\B\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\B\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\B\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\C -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\C\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\C\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\D -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\D\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\D\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\D\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\E -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\E\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\E\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\E\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\F -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\F\Controls -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\F\Controls\0 -> Spyware.MidAddle : Cleaned with backup
HKLM\SYSTEM\ControlSet003\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#PCI#VEN_10B9&DEV_5451&SUBSYS_0024103C&REV_02#3&61AAA01&0&30#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#Wave\Device Parameters\Mixer\F\Controls\1 -> Spyware.MidAddle : Cleaned with backup
HKU\S-1-5-21-3031018237-2371901463-526424978-1006\Software\AM Browser\Browser Helper Objects\{D714A94F-123A-45CC-8F03-040BCAF82AD6} -> Spyware.SideStep : Cleaned with backup
HKU\S-1-5-21-3031018237-2371901463-526424978-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D714A94F-123A-45CC-8F03-040BCAF82AD6} -> Spyware.SideStep : Cleaned with backup
:mozilla.7:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.12:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.31:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.40:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.75:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.78:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.86:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.87:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.88:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.89:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.94:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.95:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.102:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.103:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.104:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.105:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.106:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.107:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.120:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.121:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.122:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.130:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.131:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.148:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.149:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.150:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.154:C:\Documents and Settings\ForeverProfit$\Application Data\Mozilla\Firefox\Profiles\vfyaw0jq.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
C:\Documents and Settings\ForeverProfit$\Cookies\foreverprofit$@www.adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\ForeverProfit$\Local Settings\Temporary Internet Files\Content.IE5\AEEIYNZC\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Pamela Edge\Cookies\pamela edge@e-2dj6wjk4koc5mbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Pamela Edge\Cookies\pamela edge@e-2dj6wjnyukcjmkq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Pamela Edge\Cookies\pamela edge@ehg-bskyb.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Pamela Edge\Cookies\pamela edge@sales.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Pamela Edge\Cookies\pamela edge@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,9,2004_21,42,26.zip/pamela edge@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,9,2004_21,42,26.zip/pamela edge@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,9,2004_21,42,26.zip/pamela edge@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup


::Report End

#4 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 24 November 2005 - 10:25 PM

Scans with hijackthis and put a check beside these linesa nd choose FIX

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8l.hpwis.com

O3 - Toolbar: (no name) - {E606052C-C26E-4A9D-835B-BABA8BA9F1F9} - (no file)

O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll (file missing)

O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.side...et/k00719/sb028.


Then reboot and post a new log. How is it running after the reboot?

#5 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 25 November 2005 - 09:20 AM

Hi Siggyx

thanks for all your help, the computer is running very well, below is the latest log after fixing the items from the previous log I sent to you.
This scan and log was carried on my laptop, can I do the same with my desktop and forward the logs for Ewido and Hijack this for your perusal?

Here is the c+p of the finishing log below.

Many thanks.

James

Logfile of HijackThis v1.99.0
Scan saved at 10:15:53 AM, on 11/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\AM Browser\AM Browser.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\ForeverProfit$\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8l.hpwis.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SkySportsCluster] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Add Content To YMMSS Reader - res://C:\Program Files\YMMSS Reader\Tristana.exe/AddContent.js
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {04110BC2-B8B9-4CDD-8923-8C7C90F8B6A0} - http://monsterclient...20Installer.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia...ll/pcs_0025.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1104015628518
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1124291887173
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...560/mcfscan.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: HP Configuration Interface Service - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: McAfee WSC Integration - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Webroot Spy Sweeper Engine - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#6 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 25 November 2005 - 02:00 PM

Looks good :) Please post just a hiajckthis log for the next computer so I can see what we need to do.

#7 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 25 November 2005 - 04:32 PM

Thanks Siggyx, here is the Ewido log this will be followed by the latest Hijack This log.

#8 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 25 November 2005 - 04:47 PM

Sorry Siggyx, hit the button to soon.

Here is the Ewido log file c+p below.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:22:47 PM, 11/25/2005
+ Report-Checksum: 3F168AEB

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FAC94900-96D9-47fa-BA33-7EF1BBFBBCEC}\TypeLib\\ -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}\TypeLib\\ -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E77EDA01-3C56-4A96-8D08-02B42891C169} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-452981578-1003955563-848556781-1009\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{74CC49F7-EB32-4A08-B204-948962A6E3DB} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-452981578-1003955563-848556781-1009\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-21-452981578-1003955563-848556781-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-21-452981578-1003955563-848556781-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E77EDA01-3C56-4A96-8D08-02B42891C169} -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\G1QF41YZ\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_1.bkk -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_10.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_100.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_101.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_102.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_104.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_105.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_106.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_107.bkk -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_109.bkk -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_11.bkk -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_110.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_112.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_113.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_12.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_126.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_127.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_129.bkk -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_13.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_130.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_131.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_132.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_133.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_134.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_138.bkk -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_139.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_14.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_140.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_141.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_142.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_143.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_15.bkk -> Spyware.Cookie.Valuead : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_152.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_16.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_166.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_167.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_168.bkk -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_17.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_170.bkk -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_171.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_172.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_173.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_175.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_176.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_177.bkk -> Spyware.Cookie.Smartadserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_178.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_179.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_184.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_185.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_196.bkk -> Spyware.Cookie.Comclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_198.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_199.bkk -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_2.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_20.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_201.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_202.bkk -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_203.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_204.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_205.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_21.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_211.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_217.bkk -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_219.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_222.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_226.bkk -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_23.bkk -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_230.bkk -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_232.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_233.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_241.bkk -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_243.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_244.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_245.bkk -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_249.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_252.bkk -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_253.bkk -> Spyware.Cookie.Adengage : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_254.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_256.bkk -> Spyware.Cookie.Smartadserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_257.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_259.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_262.bkk -> Spyware.Cookie.Valuead : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_263.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_264.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_265.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_268.bkk -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_27.bkk -> Spyware.Cookie.Comclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_277.bkk -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_278.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_279.bkk -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_28.bkk -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_280.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_282.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_283.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_284.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_285.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_286.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_291.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_294.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_299.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_3.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_300.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_301.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_304.bkk -> Spyware.Cookie.Comclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_307.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_31.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_310.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_311.bkk -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_313.bkk -> Spyware.Cookie.X10 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_315.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_317.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_318.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_319.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_32.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_320.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_322.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_324.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_325.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_326.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_329.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_33.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_330.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_331.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_332.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_336.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_337.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_338.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_339.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_343.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_344.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_347.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_348.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_349.bkk -> Spyware.Cookie.Valuead : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_350.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_351.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_352.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_353.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_354.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_357.bkk -> Spyware.Cookie.Comclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_36.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_362.bkk -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_365.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_366.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_368.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_369.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_370.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_373.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_374.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_376.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_377.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_378.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_379.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_380.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_381.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_382.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_383.bkk -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_384.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_386.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_387.bkk -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_388.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_389.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_392.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_393.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_394.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_395.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_396.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_397.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_398.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_401.bkk -> Spyware.Cookie.Comclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_402.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_403.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_404.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_405.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_406.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_407.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_409.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_410.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_412.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_413.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_414.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_415.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_417.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_419.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_42.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_422.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_423.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_424.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_426.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_427.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_428.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_429.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_43.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_433.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_435.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_436.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_437.bkk -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_438.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_439.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_44.bkk -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_441.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_442.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_445.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_447.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_448.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_449.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_45.bkk -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_450.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_451.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_456.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_458.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_459.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_460.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_462.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_463.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_465.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_466.bkk -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_467.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_468.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_47.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_470.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_477.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_478.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_48.bkk -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_481.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_482.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_483.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_484.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_486.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_487.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_488.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_49.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_493.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_495.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_496.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_497.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_498.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_499.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_5.bkk -> Spyware.Cookie.Smartadserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_50.bkk -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_500.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_501.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_503.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_504.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_505.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_507.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_508.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_509.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_51.bkk -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_510.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_511.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_512.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_513.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_519.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_520.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_521.bkk -> Spyware.Cookie.Com : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_522.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_523.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_524.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_525.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_526.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_527.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_528.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_529.bkk -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_530.bkk -> Spyware.Cookie.Spylog : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_542.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_544.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_545.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_546.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_547.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_548.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_549.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_551.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_552.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_553.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_554.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_555.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_556.bkk -> Spyware.Cookie.Overture : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_557.bkk -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_558.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_559.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_560.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_563.bkk -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_564.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_565.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_566.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_567.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_570.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_571.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_572.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_576.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_577.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_578.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_579.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_580.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_581.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_582.bkk -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_584.bkk -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_585.bkk -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_586.bkk -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_587.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_588.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_590.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_591.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_592.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_593.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_597.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_598.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_599.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_6.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_601.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_603.bkk -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_604.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_606.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_607.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_608.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_609.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_610.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_611.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_613.bkk -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_614.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_621.bkk -> Spyware.Cookie.X10 : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_63.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_630.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_635.bkk -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_636.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_637.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_639.bkk -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_64.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_65.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_650.bkk -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_66.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_67.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_69.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_71.bkk -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_715.bkk -> Spyware.Cookie.Com : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_748.bkk -> Spyware.Cookie.Com : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_754.bkk -> Spyware.Cookie.Com : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_76.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_77.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_78.bkk -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_82.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_84.bkk -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_85.bkk -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_86.bkk -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_88.bkk -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_89.bkk -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_90.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_91.bkk -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_92.bkk -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_93.bkk -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_95.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_96.bkk -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_98.bkk -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\KillAllSpyware\backup\backup_99.bkk -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll -> Spyware.MyWebSearch : Cleaned with backup
C:\WINDOWS\system32\f3PSSavr.scr -> Spyware.MyWebSearch : Cleaned with backup


::Report End


Here is the latest Hijack this log c+p below.

Logfile of HijackThis v1.99.1
Scan saved at 5:44:00 PM, on 11/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\WinZip\WINZIP32.EXE
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\HP_Owner\Local Settings\Temp\wzcafe\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.gophersearch.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...lion&pf=desktop
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [KillAllSpyware] C:\Program Files\KillAllSpyware\KillAllSpyware.exe /quick
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O15 - Trusted Zone: http://www.carbfreehitz.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Many thanks.

James

#9 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 26 November 2005 - 01:27 AM

Looks fine :)

#10 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 26 November 2005 - 10:13 AM

Once again thank you for all your help on this :)

#11 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 26 November 2005 - 10:54 PM

Any more users logs?

#12 jpedge

jpedge

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 27 November 2005 - 09:02 AM

No that was it Siggyx. cheers mate.

#13 Siggyx

Siggyx

    SuperHelper

  • Authentic Member
  • PipPipPipPipPipPip
  • 6,776 posts

Posted 27 November 2005 - 09:58 AM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users