This is my mother in laws computer and ive done everything from adaware se to the trend micro spy removal trial. cwshredder picked up 2 cws hijacks (cws.mupdate & q2=q4-`) tryed to remove using the shredder but the computer blinked to another page and started a countdown…turned it off immeadiately and restarted and did another adaware scan to find the same problems. i downloaded HJT and placed it in its own folder on the c drive…ran a scan and got this: (any help will greatly be appreciated, this dang computer is in slow motion)
Logfile of HijackThis v1.99.1
Scan saved at 12:52:02 AM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=?????? ???????
F3 - REG:win.ini: run=?????? ???????
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1.EXE -b
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [fwwu] C:\PROGRA~1\COMMON~1\fwwu\fwwum.exe
O4 - HKCU\..\Run: [Finding Nemo ScreenMate] C:\Program Files\Finding Nemo ScreenMate\Finding Nemo ScreenMate.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/batt…x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo -
http://game1.pogo.com/applet-6.5.0.45/roul…e-ob-assets.cab
O16 - DPF: Bridge by pogo -
http://game1.pogo.com/applet-6.4.3.36/brid…e-ob-assets.cab
O16 - DPF: Canasta by pogo -
http://game1.pogo.com/applet-6.4.4.34/cana…a-ob-assets.cab
O16 - DPF: Chess by pogo -
http://game1.pogo.com/applet-6.5.0.45/ches…2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo -
http://game1.pogo.com/applet-6.4.4.34/bing…e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo -
http://game1.pogo.com/applet-6.5.0.45/gree…k-ob-assets.cab
O16 - DPF: Hearts by pogo -
http://game1.pogo.com/applet-6.4.4.34/hear…s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/mlsl…s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo -
http://game1.pogo.com/applet-6.5.0.45/free…l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo -
http://game1.pogo.com/applet-6.5.0.45/wate…l-ob-assets.cab
O16 - DPF: Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/flin…r-ob-assets.cab
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/applet-6.4.4.34/popp…2-ob-assets.cab
O16 - DPF: Quick Quack by pogo -
http://game1.pogo.com/applet-6.5.0.45/hots…k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/slot…z-ob-assets.cab
O16 - DPF: Spades by pogo -
http://game1.pogo.com/applet-6.4.4.34/spad…s-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo -
http://game1.pogo.com/applet-6.5.0.45/swee…r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game1.pogo.com/applet-6.4.4.34/worl…s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://accelerator.bellsouth.net/sdccommon…oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) -
https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) -
http://www.imgag.com/cp/install/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/2084e0bad2e841330017/…ip/RdxIE601.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} -
http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) -
http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.15.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.254 205.152.144.235
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
current log:
Logfile of HijackThis v1.99.1
Scan saved at 9:29:33 AM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=?????? ???????
F3 - REG:win.ini: run=?????? ???????
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1.EXE -b
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [fwwu] C:\PROGRA~1\COMMON~1\fwwu\fwwum.exe
O4 - HKCU\..\Run: [Finding Nemo ScreenMate] C:\Program Files\Finding Nemo ScreenMate\Finding Nemo ScreenMate.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/batt…x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo -
http://game1.pogo.com/applet-6.5.0.45/roul…e-ob-assets.cab
O16 - DPF: Bridge by pogo -
http://game1.pogo.com/applet-6.4.3.36/brid…e-ob-assets.cab
O16 - DPF: Canasta by pogo -
http://game1.pogo.com/applet-6.4.4.34/cana…a-ob-assets.cab
O16 - DPF: Chess by pogo -
http://game1.pogo.com/applet-6.5.0.45/ches…2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo -
http://game1.pogo.com/applet-6.4.4.34/bing…e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo -
http://game1.pogo.com/applet-6.5.0.45/gree…k-ob-assets.cab
O16 - DPF: Hearts by pogo -
http://game1.pogo.com/applet-6.4.4.34/hear…s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/mlsl…s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo -
http://game1.pogo.com/applet-6.5.0.45/free…l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo -
http://game1.pogo.com/applet-6.5.0.45/wate…l-ob-assets.cab
O16 - DPF: Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/flin…r-ob-assets.cab
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/applet-6.4.4.34/popp…2-ob-assets.cab
O16 - DPF: Quick Quack by pogo -
http://game1.pogo.com/applet-6.5.0.45/hots…k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/slot…z-ob-assets.cab
O16 - DPF: Spades by pogo -
http://game1.pogo.com/applet-6.4.4.34/spad…s-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo -
http://game1.pogo.com/applet-6.5.0.45/swee…r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game1.pogo.com/applet-6.4.4.34/worl…s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://accelerator.bellsouth.net/sdccommon…oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) -
https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) -
http://www.imgag.com/cp/install/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/2084e0bad2e841330017/…ip/RdxIE601.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} -
http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) -
http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.15.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
ok this is the third and final part of the original ewido scan log:
Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~425274.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~425458.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~426669.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~428722.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~429438.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~431182.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~432716.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~432985.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~433295.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~437131.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~438175.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~439040.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~439802.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~441084.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~445562.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~445876.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~446468.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~446559.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~448103.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~448686.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~449745.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~450216.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~450692.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~454119.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~455071.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~457008.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~458699.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~463452.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~463910.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~464073.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~464249.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~466773.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~467982.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469436.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469736.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469948.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~471740.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~472175.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~475421.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~475857.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~481757.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~482442.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~483041.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~494200.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~495868.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~496882.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~507463.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~508314.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~509351.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~509560.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~510255.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~511830.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~511911.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~512677.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~512738.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~513767.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~5153.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~515432.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~516643.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~519137.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~520542.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~521247.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~522571.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~523593.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~52561.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~52974.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~532517.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~533354.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~535616.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~537543.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~537988.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~539070.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~541201.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~542982.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~543856.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~544273.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~544423.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~546707.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~552079.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~552802.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~554453.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~555840.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~566581.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~569276.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~570214.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~572309.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~576281.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~576405.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~577851.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~578126.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~583047.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~584886.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~586207.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~590216.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~590732.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~592801.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~595655.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~595904.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~599646.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~600931.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~602403.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~604322.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~606770.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~608391.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~609535.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~610235.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~61337.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~614479.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~614901.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619377.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619836.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619999.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~623997.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~624797.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~626051.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~629826.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~630139.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~635368.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~636820.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~63998.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~640851.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~642686.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~649610.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~649804.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~65083.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~652028.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~652340.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~65352.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~655497.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~656743.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~657735.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~658584.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~660785.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664260.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664616.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664821.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664973.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~666975.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~668412.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~669351.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~670867.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~673788.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~675934.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~678549.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~683309.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684191.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684268.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684723.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684824.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~687810.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~689057.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~689571.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~690401.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~690500.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~691458.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~693074.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~693174.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~696225.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~696936.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698723.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698792.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698794.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~700049.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~705639.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~707116.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711163.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711569.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711928.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~712699.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~713299.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~715535.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~716483.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~71759.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~717734.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~720205.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~721576.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~730462.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~731222.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~732813.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~732933.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~733646.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~733867.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~736114.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~737730.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~738158.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~738665.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741364.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741712.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741845.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~742227.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~744144.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~744951.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~752062.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~756265.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~760016.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~760816.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~761161.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762285.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762609.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762815.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~767696.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~773052.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~774949.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~776632.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~780024.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~781044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~782586.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~785290.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~788748.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~791065.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~792797.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~795401.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~799013.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~801467.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~802638.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~808044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~810358.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~818171.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~818335.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~819799.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~820066.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823653.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823764.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823986.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~828149.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~828834.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~829831.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831062.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831287.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831772.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~834285.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~836044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~852710.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~869527.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~872319.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~875337.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~878632.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~87940.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~880198.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~880551.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~882888.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~886607.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~890733.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~891338.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~897966.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~898035.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~898519.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~90507.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~907472.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~908927.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~909436.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~919235.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~924910.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925396.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925671.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925824.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~926148.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~926911.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931189.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931366.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931451.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~932103.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~932911.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~933825.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~934417.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~935601.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~940308.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~943589.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~947805.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~950205.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~954639.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~956997.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~957231.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~962573.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~962779.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~963338.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~965513.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~968345.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~972182.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~976599.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~977998.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~978126.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~978834.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~981644.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~982920.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~983891.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~985086.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~985450.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~989894.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~993275.tmp -> Downloader.WinTool : Cleaned with backup
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\newdotnet7_14.dll -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,11,2005_21,30,35.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,11,2005_21,30,35.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,9,2005_17,54,37.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/[removed][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_15,3,20.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/[removed][2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,6,2004_16,39,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_12,53,55.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_12,53,55.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,25,2004_23,57,48.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,25,2004_23,57,48.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,29,2004_20,41,3.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,3,2004_21,38,9.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,3,2004_21,38,9.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,4,2004_21,59,4.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,9,2004_22,44,4.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,9,2004_22,44,4.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,26,2005_18,37,11.zip/csutil.dll -> Spyware.Comet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,26,2005_18,37,11.zip/fileutil.dll -> Spyware.Comet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,23,2004_17,36,10.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,23,2004_22,56,30.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,25,2004_20,26,48.zip/[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,27,2004_15,45,5.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_17,3,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_23,3,10.zip/[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_23,3,10.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_9,34,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,29,2004_17,44,47.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,12,2005_18,6,25.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,12,2005_18,6,25.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,16,2005_17,1,56.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,16,2005_17,1,56.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,2,2004_20,25,1.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,3,2004_16,41,20.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,5,2004_10,16,54.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,6,2004_18,25,4.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,8,2004_14,31,32.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,8,2004_8,54,40.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,22,2005_2,32,24.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,6,2005_19,44,10.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,10,2004_17,23,58.zip/[removed][2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,12,2004_22,59,51.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,14,2004_6,55,39.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,14,2004_9,4,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,15,2004_14,31,42.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/Hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/Hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,24,2004_0,59,38.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_0,16,50.zip/mary@gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_0,16,50.zip/mary@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_12,28,33.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,37,40.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,37,40.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,7,39.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_11,59,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_15,41,7.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_16,22,34.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_16,22,34.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_9,46,7.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_9,46,7.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,27,2004_22,5,51.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,28,2004_12,4,24.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,6,2005_16,1,41.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,8,2004_22,59,58.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,8,2004_22,59,58.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,9,2005_9,24,1.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,9,2005_9,24,1.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,1,2004_22,59,21.zip/[removed][2].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,1,2004_22,59,21.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,10,2004_16,42,54.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,10,2004_16,42,54.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,14,2004_15,8,24.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,17,2004_17,35,29.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,20,2004_16,33,38.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2005_0,19,27.zip/[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,24,2004_1,16,19.zip/[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,24,2005_5,13,18.zip/[removed][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,3,2004_12,5,56.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\
ok here is the scan logs i just ran, they are much cleaner but the computer performance hasn't changed
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 3:21:51 PM, 1/24/2006
+ Report-Checksum: E0CDB77D
+ Scan result:
C:\Documents and Settings\Mary\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
::Report End
ok heres the hijackthis log from today:
Logfile of HijackThis v1.99.1
Scan saved at 3:57:37 PM, on 1/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\repair\faxxml.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Mary\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=?????? ???????
F3 - REG:win.ini: run=?????? ???????
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/batt…x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo -
http://game1.pogo.com/applet-6.5.0.45/roul…e-ob-assets.cab
O16 - DPF: Bridge by pogo -
http://game1.pogo.com/applet-6.4.3.36/brid…e-ob-assets.cab
O16 - DPF: Canasta by pogo -
http://game1.pogo.com/applet-6.4.4.34/cana…a-ob-assets.cab
O16 - DPF: Chess by pogo -
http://game1.pogo.com/applet-6.5.0.45/ches…2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo -
http://game1.pogo.com/applet-6.4.4.34/bing…e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo -
http://game1.pogo.com/applet-6.5.0.45/gree…k-ob-assets.cab
O16 - DPF: Hearts by pogo -
http://game1.pogo.com/applet-6.4.4.34/hear…s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/mlsl…s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo -
http://game1.pogo.com/applet-6.5.0.45/free…l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo -
http://game1.pogo.com/applet-6.5.0.45/wate…l-ob-assets.cab
O16 - DPF: Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/flin…r-ob-assets.cab
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/applet-6.4.4.34/popp…2-ob-assets.cab
O16 - DPF: Quick Quack by pogo -
http://game1.pogo.com/applet-6.5.0.45/hots…k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/slot…z-ob-assets.cab
O16 - DPF: Spades by pogo -
http://game1.pogo.com/applet-6.4.4.34/spad…s-ob-assets.cab
O16 - DPF: Stax by pogo -
http://game1.pogo.com/applet-6.5.0.45/stax…x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo -
http://game1.pogo.com/applet-6.5.0.45/swee…r-ob-assets.cab
O16 - DPF: Video Poker by pogo -
http://game1.pogo.com/applet-6.5.0.45/vide…r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game1.pogo.com/applet-6.4.4.34/worl…s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://accelerator.bellsouth.net/sdccommon…oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) -
https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) -
http://www.imgag.com/cp/install/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://207.188.7.150/2084e0bad2e841330017/…ip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} -
http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) -
http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.15.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
thank you for your time and please advise what steps to take next
Chuck
ok got everything done. here's a few things i need to note:
1. start up is still superslow…hourglass stays on for approximately 1hr and 20 minutes (i timed it this time)
2. when starting up this time, trend micro anti spyware venus flytrap monitoring program picked up many proxy server changes to the web browsing configuration…i allowed all of them…considering we made so many changes….these warnings came up through out the 1 hr and 20 minute startup.
3. the last program that came up in startup was the bellsouth accelerator…this is the program i need to be able to access the internet…even though i can connect to the internet right away after start up…i get "IE explorer cannot find server or dns error" immeadiately when the IE window opens…i can get to the internet during this time with other programs such as any of the spyware/virus update programs (they seem to be able to access the net) as well as yahoo messenger access the net just fine during the startup period.
4. ive tryed different sites using IE during this startup period all trys get the same "IE explorer cannot find server or dns error"
5. after the bell accelarator program loads (last program that starts up, 1 hr 20 minutes after reboot) i am able to access the internet through IE.
6. right after reboot…i noticed that the pointer now moves freely during start up (no stalls or freezeups like it used to do, even though the hour glass is still present)
7. actions seem to be quicker with faster reponse times…like when i press the start button…the menu pops up immeadiately…before there was a delay….when i click on folders they pop right open now displaying the contents..before there was a delay…programs seem to start quicker (except for startup)
8. after the startup (1 hr 20 minutes…lol) is complete i can access the web…seems pages load quicker…no delays or "IE explorer cannot find server or dns errors"
9. previously i could surf for an hour or so then i would get a "unknown error -1" in IE and i wouldnt be able to surf again without a reboot…which would take a longtime (1 hr 20 mnutes) to get back on IE…I dont know the status of this yet considering i havent had that problem as of yet.
20. overall quicker speed while navagating through windows and browsing the web, startup still a big problem.
Let me know what to do from here and thank you for what you have done so far.
here's the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 12:22:29 AM, on 1/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/batt…x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo -
http://game1.pogo.com/applet-6.5.0.45/roul…e-ob-assets.cab
O16 - DPF: Bridge by pogo -
http://game1.pogo.com/applet-6.4.3.36/brid…e-ob-assets.cab
O16 - DPF: Canasta by pogo -
http://game1.pogo.com/applet-6.4.4.34/cana…a-ob-assets.cab
O16 - DPF: Chess by pogo -
http://game1.pogo.com/applet-6.5.0.45/ches…2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo -
http://game1.pogo.com/applet-6.4.4.34/bing…e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo -
http://game1.pogo.com/applet-6.5.0.45/gree…k-ob-assets.cab
O16 - DPF: Hearts by pogo -
http://game1.pogo.com/applet-6.4.4.34/hear…s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/mlsl…s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo -
http://game1.pogo.com/applet-6.5.0.45/free…l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo -
http://game1.pogo.com/applet-6.5.0.45/wate…l-ob-assets.cab
O16 - DPF: Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/flin…r-ob-assets.cab
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/applet-6.4.4.34/popp…2-ob-assets.cab
O16 - DPF: Quick Quack by pogo -
http://game1.pogo.com/applet-6.5.0.45/hots…k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/slot…z-ob-assets.cab
O16 - DPF: Spades by pogo -
http://game1.pogo.com/applet-6.4.4.34/spad…s-ob-assets.cab
O16 - DPF: Stax by pogo -
http://game1.pogo.com/applet-6.5.0.45/stax…x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo -
http://game1.pogo.com/applet-6.5.0.45/swee…r-ob-assets.cab
O16 - DPF: Video Poker by pogo -
http://game1.pogo.com/applet-6.5.0.45/vide…r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game1.pogo.com/applet-6.4.4.34/worl…s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://accelerator.bellsouth.net/sdccommon…oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) -
https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
ok…startup this time only 40 minutes until the bellsouth accellerator came up in the tray next to the time and allowed access to the IE and the net.
i cant really tell adifference in the preformance now and when we last talked. Still borwses great both online(after starting up) and through windows. Startup cutdown to 40 minutes…which is still just way too slow…lol.
while your looking at this, im gonna take the bellsouth accellerator off the startup. The internet connection used to work fine without it they said it would be faster if we used it in conjuction with our ISP.
I got a feeling that IE in the startup program list starts after the propel bellsouth accelerator…if the accelerator is hanging up during startup (or just takes an incredibly long tome to start) this would hold up the startup of IE. So given the above, if i take the accellerator off the startup list maybe i can get to the internet quicker through IE since it wont have to wait til the Accellerator starts. Who KNows…I'll give it a try.
Here's another Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 7:35:17 PM, on 1/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Mary\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Animal Ark by pogo -
http://www.pogo.com/applet-6.5.1.24/animal/animal-en_US.cab
O16 - DPF: Battle Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/batt…x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo -
http://game1.pogo.com/applet-6.5.0.45/roul…e-ob-assets.cab
O16 - DPF: Bridge by pogo -
http://game1.pogo.com/applet-6.4.3.36/brid…e-ob-assets.cab
O16 - DPF: Canasta by pogo -
http://game1.pogo.com/applet-6.4.4.34/cana…a-ob-assets.cab
O16 - DPF: Chess by pogo -
http://game1.pogo.com/applet-6.5.0.45/ches…2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo -
http://game1.pogo.com/applet-6.4.4.34/bing…e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo -
http://game1.pogo.com/applet-6.5.0.45/gree…k-ob-assets.cab
O16 - DPF: Hearts by pogo -
http://game1.pogo.com/applet-6.4.4.34/hear…s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/mlsl…s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo -
http://game1.pogo.com/applet-6.5.0.45/free…l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo -
http://game1.pogo.com/applet-6.5.0.45/wate…l-ob-assets.cab
O16 - DPF: Phlinx by pogo -
http://game1.pogo.com/applet-6.5.0.45/flin…r-ob-assets.cab
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/applet-6.4.4.34/popp…2-ob-assets.cab
O16 - DPF: Quick Quack by pogo -
http://game1.pogo.com/applet-6.5.0.45/hots…k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo -
http://game1.pogo.com/applet-6.5.0.45/slot…z-ob-assets.cab
O16 - DPF: Spades by pogo -
http://game1.pogo.com/applet-6.4.4.34/spad…s-ob-assets.cab
O16 - DPF: Stax by pogo -
http://game1.pogo.com/applet-6.5.0.45/stax…x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo -
http://game1.pogo.com/applet-6.5.0.45/swee…r-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo -
http://game1.pogo.com/applet-6.5.1.24/hold…oldem-en_US.cab
O16 - DPF: Video Poker by pogo -
http://game1.pogo.com/applet-6.5.0.45/vide…r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game1.pogo.com/applet-6.4.4.34/worl…s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://accelerator.bellsouth.net/sdccommon…oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) -
https://password.bellsouth.net/sdccommon/do…oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe