Not sure why the first paste came up short. Looks ok this time. I pulled out the cookies. Not sure what is restore points since all lines seem to have the word restore in them. New HJT included.
Thank you for your time... Brad
Logfile of HijackThis v1.99.1
Scan saved at 5:50:58 PM, on 3/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Tools\Spyware Tools\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\ffpsrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\tools\CompuPicPro\ScsiAccess.exe
C:\tools\Alarm\AlarmMonitor.exe
C:\tools\PerfectDisk\PerfectDisk\PDSched.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\tools\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Tools\HotKeyz\HotKeyz.exe
C:\tools\Alarm\Alarm Tray.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Tools\SnagIt 7\SnagIt32.exe
C:\Tools\RemindMe\RemindMe.exE
C:\tools\Alarm\Alarm.exe
C:\Tools\Traybar\Traybar.exe
C:\Tools\SnagIt 7\TSCHelp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Tools\ClipCache\clipc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Tools\Spyware Tools\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://charter.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://charter.net/
N3 - Netscape 7: user_pref("browser.startup.homepage", "
http://crackspider.net/"); (C:\Documents and Settings\Theurich Family\Application Data\Mozilla\Profiles\default\0lnqtvhv.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Theurich Family\Application Data\Mozilla\Profiles\default\0lnqtvhv.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Tools\RoboForm\roboform.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [Show missed alarms] C:\tools\Alarm\Alarm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ClipCache] C:\Tools\ClipCache\clipc.exe /wait 3
O4 - HKCU\..\Run: [FreeRAM XP] "C:\tools\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [HotKeyz.exe Startup] C:\Tools\HotKeyz\HotKeyz.exe Startup
O4 - Startup: RemindMe.lnk = C:\Tools\RemindMe\RemindMe.exE
O4 - Startup: Traybar.lnk = C:\Tools\Traybar\Traybar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: SnagIt 7.lnk = C:\Tools\SnagIt 7\SnagIt32.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Answers... - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Tools\RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms - file://C:\Tools\RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Tools\RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Tools\RoboForm\RoboFormComSavePass.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
https://install.char...bin/tgctlcm.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_2.1.1.74.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1131848612778
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) -
http://a532.g.akamai...0/installer.exe
O20 - Winlogon Notify: URL - C:\WINDOWS\system32\hrr0059me.dll
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\r6p8lg7u16.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Talking Alarm Clock user logon monitor (AlarmClockMonitor) - Cinnamon Software Inc. - C:\tools\Alarm\AlarmMonitor.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Tools\Spyware Tools\ewido anti-malware\ewidoctrl.exe
O23 - Service: File and Folder Protector (FileAndFolderProtector_S) - Unknown owner - C:\WINDOWS\System32\ffpsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\tools\PerfectDisk\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\tools\PerfectDisk\PerfectDisk\PDSched.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\tools\CompuPicPro\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Unknown owner - C:\Tools\Spyware Tools\Spy Sweeper\WRSSSDK.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\tools\TuneUp 2006\WinStylerThemeSvc.exe
*********
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 5:24:05 PM, 3/4/2006
+ Report-Checksum: 5F0B5A12
+ Scan result:
C:\Documents and Settings\Theurich Family\Local Settings\Temp\temp.frF78B -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0065875.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066895.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066927.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066933.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066957.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066961.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066964.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066967.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066969.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066974.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066979.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066981.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066987.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066993.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066996.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP199\A0066999.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067007.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067012.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067013.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067017.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067018.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067019.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067031.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067043.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067047.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067048.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067049.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067065.dll -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067067.exe -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067068.exe -> Downloader.Agent.afi : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067070.exe -> Downloader.Qoologic.bh : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067074.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067079.exe -> Hijacker.StartPage.aib : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067080.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067081.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067177.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067185.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067283.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067302.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP200\A0067372.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067381.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067383.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067384.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067403.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067439.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067441.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067447.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067451.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067453.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067459.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067463.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067476.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067481.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP202\A0067483.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067489.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067494.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067499.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067500.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067508.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067509.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067514.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067518.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067519.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067524.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067526.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067530.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067531.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067539.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067543.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP203\A0067545.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067607.exe -> Downloader.Small.abd : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067612.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067616.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067619.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067633.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067644.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067648.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067667.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0067671.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068667.dll -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068668.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068669.exe -> Trojan.VB.tg : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068670.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068680.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068695.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068701.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068705.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068707.exe -> Downloader.VB.tw : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068708.exe -> Downloader.VB.tw : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068710.dll -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068711.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068715.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068720.exe -> Dropper.VB.lu : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068721.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068727.exe -> Downloader.VB.xr : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068728.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068730.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0068735.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070739.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070741.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070746.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070748.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070753.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070762.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070768.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070769.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070776.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070777.ocx -> Downloader.VB.ov : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070778.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070779.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070780.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070781.exe -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070782.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070783.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070784.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070785.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070786.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070787.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070788.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070789.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070790.exe -> Downloader.VB.uc : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070791.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070792.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070797.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070798.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070806.exe -> Hijacker.Small.is : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070811.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070814.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070815.exe -> Hijacker.StartPage.aib : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070816.exe -> Adware.ZenoSearch : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070817.exe -> Downloader.Adload.v : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070818.exe -> Downloader.Agent.afi : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070820.exe -> Adware.Trymedia : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070821.exe -> Dropper.VB.lu : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070822.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070823.exe -> Downloader.Adload.v : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070824.exe -> Dropper.Agent.hl : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0071797.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0073801.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0073804.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0073809.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0073812.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0073817.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0074815.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0075814.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0075826.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP208\A0075832.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075877.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075881.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075902.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075903.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075904.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075905.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075906.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075907.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075908.dll -> Adware.Suggestor : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075914.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075936.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075956.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075970.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0075980.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0076018.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0076019.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0076026.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0076033.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0076038.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077037.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077040.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077045.DLL -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077049.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077074.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0077075.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0078074.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0079077.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP209\A0080077.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0080084.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0080088.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0081087.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0081103.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0082088.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0083088.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0083112.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0083117.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0084115.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0085115.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086126.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086133.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086134.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086135.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086136.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086137.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086138.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086139.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086140.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086141.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086142.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086143.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086144.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086145.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086146.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086147.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086148.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086149.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086150.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086151.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086153.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP210\A0086154.dll -> Adware.Look2Me : Cleaned with backup
D:\System Volume Information\_restore{787676C9-C509-431A-ADED-66D76243DDAC}\RP206\A0070825.exe -> Hijacker.Small.is : Cleaned with backup
::Report End
Edited by OnN2nN5, 04 March 2006 - 08:09 PM.