Here is the latest Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:58 AM, on 4/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\tony\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcy/default…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://rd.yahoo.com/customize/sbcy/default…oo.sbc.com/dial
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {1719F921-098E-1247-3D73-596817F29FFC} - C:\WINDOWS\wzfrciyd.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yvakt Class - {2335EA94-74D6-46B4-BA93-8567DAC6CC9B} - C:\WINDOWS\system32\fpdrnznx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6FCDCC60-FB19-3C5A-B9BD-C38BD9662FA1} - C:\WINDOWS\wzfrciyd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: BMG3.LongTooth - {8110581C-FEA4-47AC-ADBC-DE958DD0F354} - C:\WINDOWS\system32\{8110581C-FEA4-47AC-ADBC-DE958DD0F354}.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [3A3338353C36403D3] 261F242128222C2.exe
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [8951193] C:\PROGRA~1\8951193\8951193.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: eFax DllCmd 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} -
http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/pm/activex/eBay_E…l_v1-0-3-36.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1107318035437
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) -
http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Filter: text/html - {7B1EE13A-FE1E-48B0-AC2C-8ACC5E3BB7CB} - C:\WINDOWS\system32\fpdrnznx.dll
O20 - AppInit_DLLs: abmnjlob.dll,Runner.dll,ogkceejb.dll,cmstart.dll,Runner.dll,cmstart.dll,EQMini.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
Here is the Spysweeper Log:
8:50 PM: | Start of Session, Saturday, April 01, 2006 |
8:50 PM: Spy Sweeper started
8:50 PM: Sweep initiated using definitions version 646
8:50 PM: Starting Memory Sweep
8:52 PM: Found Adware: fullcontext
8:52 PM: Detected running threat: C:\WINDOWS\system32\Runner.dll (ID = 257233)
8:53 PM: Detected running threat: C:\Program Files\EQArticle\EQArticle.exe (ID = 238997)
8:54 PM: Memory Sweep Complete, Elapsed Time: 00:03:25
8:54 PM: Starting Registry Sweep
8:54 PM: Found Adware: marketscore
8:54 PM: HKLM\software\microsoft\windows\currentversion\run\ || oss (ID = 134749)
8:54 PM: Found Trojan Horse: trojan_backdoor_retro64
8:54 PM: HKCR\clsid\{288c5f13-7e52-4ada-a32e-f5bf9d125f99}\ (20 subtraces) (ID = 144994)
8:54 PM: HKCR\interface\{450b9e4d-4014-4de3-b34e-014a81468293}\ (8 subtraces) (ID = 144995)
8:54 PM: HKLM\software\classes\clsid\{288c5f13-7e52-4ada-a32e-f5bf9d125f99}\ (20 subtraces) (ID = 144999)
8:54 PM: HKLM\software\classes\interface\{450b9e4d-4014-4de3-b34e-014a81468293}\ (8 subtraces) (ID = 145000)
8:54 PM: HKLM\software\classes\typelib\{c7f00a9a-f1bc-436e-82c7-e8cae6fd67f7}\ (9 subtraces) (ID = 145003)
8:54 PM: HKCR\typelib\{c7f00a9a-f1bc-436e-82c7-e8cae6fd67f7}\ (9 subtraces) (ID = 145004)
8:54 PM: Found Adware: zenosearchassistant
8:54 PM: HKLM\software\microsoft\windows\currentversion\app management\arpcache\zeno search assistant\ (2 subtraces) (ID = 147930)
8:54 PM: HKLM\software\microsoft\windows\currentversion\app management\arpcache\enhanced ads by zeno\ (2 subtraces) (ID = 147931)
8:54 PM: Found Trojan Horse: trojan-downloader-exfol
8:54 PM: HKLM\software\microsoft\code store database\distribution units\{444b911e-6e55-4a11-b3e9-0d3e21ae0437}\ (8 subtraces) (ID = 1059552)
8:54 PM: Found Adware: quicklink search toolbar
8:54 PM: HKCR\fseytdc.ariaqudok\ (3 subtraces) (ID = 1180460)
8:54 PM: HKCR\fseytdc.ariaqudok.1\ (3 subtraces) (ID = 1180464)
8:54 PM: HKCR\fseytdc.yvakt\ (3 subtraces) (ID = 1180468)
8:54 PM: HKCR\fseytdc.yvakt.1\ (3 subtraces) (ID = 1180472)
8:54 PM: HKLM\software\classes\fseytdc.ariaqudok\ (3 subtraces) (ID = 1180510)
8:54 PM: HKLM\software\classes\fseytdc.ariaqudok.1\ (3 subtraces) (ID = 1180514)
8:54 PM: HKLM\software\classes\fseytdc.yvakt\ (3 subtraces) (ID = 1180518)
8:54 PM: HKLM\software\classes\fseytdc.yvakt.1\ (3 subtraces) (ID = 1180522)
8:54 PM: HKCR\clsid\{994d478a-45d0-4db4-ae77-288b1e346e99}\ (4 subtraces) (ID = 1190252)
8:54 PM: HKCR\typelib\{1b8b502e-455b-4022-be77-fb6d9f808a18}\ (9 subtraces) (ID = 1190257)
8:54 PM: HKLM\software\classes\clsid\{994d478a-45d0-4db4-ae77-288b1e346e99}\ (4 subtraces) (ID = 1190291)
8:54 PM: HKLM\software\classes\typelib\{1b8b502e-455b-4022-be77-fb6d9f808a18}\ (9 subtraces) (ID = 1190296)
8:54 PM: Found Adware: superbar
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\ (84 subtraces) (ID = 143242)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\ || client update (ID = 143243)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\ || force update (ID = 143244)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ (68 subtraces) (ID = 143247)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || 7search (ID = 143248)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || ah-ha (ID = 143249)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || alexa (ID = 143250)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || aol.co.uk (ID = 143251)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || askjeeves.co.uk (ID = 143252)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || askjeeves.com (ID = 143253)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || dogpile (ID = 143254)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || espotting (ID = 143255)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || fireball (ID = 143256)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || freenet (ID = 143257)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || goclick (ID = 143258)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google.ch (ID = 143259)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google.co.uk (ID = 143260)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google.de (ID = 143261)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google.fr (ID = 143262)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google.it (ID = 143263)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || google (ID = 143264)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || greasycow (ID = 143265)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || hotbot (ID = 143266)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || infospace (ID = 143267)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || iwon (ID = 143268)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || kanoodle (ID = 143269)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || libero (ID = 143270)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lookseek (ID = 143271)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || looksmart.co.uk (ID = 143272)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || looksmart (ID = 143273)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos.co.uk (ID = 143274)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos.de (ID = 143275)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos.es (ID = 143276)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos.fr (ID = 143277)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos.it (ID = 143278)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || lycos (ID = 143279)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.ch (ID = 143280)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.co.uk (ID = 143281)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.de (ID = 143282)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.es (ID = 143283)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.fr (ID = 143284)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.it (ID = 143285)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn.se (ID = 143286)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || msn (ID = 143287)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || passagen (ID = 143288)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || search.ch (ID = 143289)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || search123 (ID = 143290)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || search (ID = 143291)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || spray (ID = 143292)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || supereva (ID = 143293)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || t-online (ID = 143294)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || tiscali (ID = 143295)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || virgilio (ID = 143296)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || voila (ID = 143297)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || web (ID = 143298)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || xuppa (ID = 143299)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.co.uk (ID = 143300)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.de (ID = 143301)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.es (ID = 143302)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.fr (ID = 143303)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.it (ID = 143304)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo.se (ID = 143305)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\superbar\engines\ || yahoo (ID = 143306)
8:54 PM: Found Adware: big fish games toolbar
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\bfgtoolbar\ (36 subtraces) (ID = 941691)
8:54 PM: HKU\WRSS_Profile_S-1-5-21-1993962763-1035525444-1801674531-1006\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (ID = 941730)
8:54 PM: HKU\S-1-5-21-1993962763-1035525444-1801674531-1003\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (ID = 941730)
8:54 PM: HKU\S-1-5-21-1993962763-1035525444-1801674531-1003\software\eqarticle\ (8 subtraces) (ID = 1139452)
8:54 PM: HKU\S-1-5-21-1993962763-1035525444-1801674531-1003\software\microsoft\windows\currentversion\run\ || eqarticle (ID = 1139465)
8:54 PM: HKU\S-1-5-21-1993962763-1035525444-1801674531-1003\software\eqadvice\ (7 subtraces) (ID = 1190273)
8:54 PM: HKU\S-1-5-21-1993962763-1035525444-1801674531-1003\software\fcadvice\ (3 subtraces) (ID = 1190282)
8:54 PM: HKU\S-1-5-18\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (ID = 941730)
8:54 PM: Registry Sweep Complete, Elapsed Time:00:00:22
8:54 PM: Starting Cookie Sweep
8:54 PM: Found Spy Cookie: adknowledge cookie
8:54 PM: paul@adknowledge[2].txt (ID = 2072)
8:54 PM: Found Spy Cookie: hbmediapro cookie
8:54 PM: [removed][2].txt (ID = 2768)
8:54 PM: Found Spy Cookie: ask cookie
8:54 PM: paul@ask[1].txt (ID = 2245)
8:54 PM: Found Spy Cookie: belnk cookie
8:54 PM: [removed][2].txt (ID = 2293)
8:54 PM: paul@belnk[1].txt (ID = 2292)
8:54 PM: [removed][2].txt (ID = 2293)
8:54 PM: myyra94@adknowledge[2].txt (ID = 2072)
8:54 PM: myyra94@ask[1].txt (ID = 2245)
8:54 PM: myyra94@belnk[1].txt (ID = 2292)
8:54 PM: [removed][2].txt (ID = 2293)
8:54 PM: Found Spy Cookie: screensavers.com cookie
8:54 PM: [removed][1].txt (ID = 3298)
8:54 PM: Found Spy Cookie: clickads cookie
8:54 PM: [removed][1].txt (ID = 4643)
8:54 PM: [removed][1].txt (ID = 3298)
8:54 PM: Found Spy Cookie: 3 cookie
8:54 PM: tony@3[2].txt (ID = 1959)
8:54 PM: Found Spy Cookie: 412 cookie
8:54 PM: tony@412[1].txt (ID = 1969)
8:54 PM: Found Spy Cookie: 447 cookie
8:54 PM: tony@447[1].txt (ID = 1973)
8:54 PM: Found Spy Cookie: 64.62.232 cookie
8:54 PM: tony@64.62.232[1].txt (ID = 1987)
8:54 PM: tony@64.62.232[2].txt (ID = 1987)
8:54 PM: Found Spy Cookie: 735 cookie
8:54 PM: tony@735[1].txt (ID = 2009)
8:54 PM: Found Spy Cookie: 888 cookie
8:54 PM: tony@888[1].txt (ID = 2019)
8:54 PM: tony@888[2].txt (ID = 2019)
8:54 PM: Found Spy Cookie: websponsors cookie
8:54 PM: [removed][2].txt (ID = 3665)
8:54 PM: Found Spy Cookie: go.com cookie
8:54 PM: [removed][1].txt (ID = 2729)
8:54 PM: [removed][2].txt (ID = 2729)
8:54 PM: Found Spy Cookie: about cookie
8:54 PM: tony@about[1].txt (ID = 2037)
8:54 PM: Found Spy Cookie: reunion cookie
8:54 PM: [removed][1].txt (ID = 3256)
8:54 PM: Found Spy Cookie: yieldmanager cookie
8:54 PM: [removed][2].txt (ID = 3751)
8:54 PM: Found Spy Cookie: adecn cookie
8:54 PM: tony@adecn[2].txt (ID = 2063)
8:54 PM: tony@adknowledge[2].txt (ID = 2072)
8:54 PM: Found Spy Cookie: adlegend cookie
8:54 PM: tony@adlegend[1].txt (ID = 2074)
8:54 PM: [removed][2].txt (ID = 2768)
8:54 PM: Found Spy Cookie: precisead cookie
8:54 PM: [removed][1].txt (ID = 3182)
8:54 PM: Found Spy Cookie: specificclick.com cookie
8:54 PM: [removed][2].txt (ID = 3400)
8:54 PM: Found Spy Cookie: adprofile cookie
8:54 PM: tony@adprofile[1].txt (ID = 2084)
8:54 PM: Found Spy Cookie: adrevolver cookie
8:54 PM: tony@adrevolver[1].txt (ID = 2088)
8:54 PM: tony@adrevolver[3].txt (ID = 2088)
8:54 PM: Found Spy Cookie: addynamix cookie
8:54 PM: [removed][2].txt (ID = 2062)
8:54 PM: Found Spy Cookie: cc214142 cookie
8:54 PM: tony@ads.cc214142[2].txt (ID = 2367)
8:54 PM: Found Spy Cookie: revenue.net cookie
8:54 PM: [removed][1].txt (ID = 3258)
8:54 PM: Found Spy Cookie: apmebf cookie
8:54 PM: tony@apmebf[2].txt (ID = 2229)
8:54 PM: Found Spy Cookie: atwola cookie
8:54 PM: [removed][2].txt (ID = 2256)
8:54 PM: Found Spy Cookie: falkag cookie
8:54 PM: [removed][1].txt (ID = 2650)
8:54 PM: [removed][1].txt (ID = 2650)
8:54 PM: tony@ask[1].txt (ID = 2245)
8:54 PM: [removed][1].txt (ID = 2293)
8:54 PM: tony@atwola[2].txt (ID = 2255)
8:54 PM: Found Spy Cookie: azjmp cookie
8:54 PM: tony@azjmp[2].txt (ID = 2270)
8:54 PM: Found Spy Cookie: banners cookie
8:54 PM: tony@banners[1].txt (ID = 2282)
8:54 PM: Found Spy Cookie: banner cookie
8:54 PM: tony@banner[1].txt (ID = 2276)
8:54 PM: tony@belnk[1].txt (ID = 2292)
8:54 PM: Found Spy Cookie: bizrate cookie
8:54 PM: tony@bizrate[2].txt (ID = 2308)
8:54 PM: Found Spy Cookie: megago cookie
8:54 PM: [removed][2].txt (ID = 2983)
8:54 PM: Found Spy Cookie: bluestreak cookie
8:54 PM: tony@bluestreak[2].txt (ID = 2314)
8:54 PM: Found Spy Cookie: enhance cookie
8:54 PM: [removed][1].txt (ID = 2614)
8:54 PM: Found Spy Cookie: zedo cookie
8:54 PM: [removed][1].txt (ID = 3763)
8:54 PM: Found Spy Cookie: casalemedia cookie
8:54 PM: tony@casalemedia[1].txt (ID = 2354)
8:54 PM: Found Spy Cookie: cassava cookie
8:54 PM: tony@cassava[1].txt (ID = 2362)
8:54 PM: tony@cc214142[2].txt (ID = 2366)
8:54 PM: Found Spy Cookie: classmates cookie
8:54 PM: tony@classmates[1].txt (ID = 2384)
8:54 PM: [removed][1].txt (ID = 2038)
8:54 PM: Found Spy Cookie: tickle cookie
8:54 PM: [removed][1].txt (ID = 3530)
8:54 PM: Found Spy Cookie: dealtime cookie
8:54 PM: tony@dealtime[2].txt (ID = 2505)
8:54 PM: Found Spy Cookie: did-it cookie
8:54 PM: tony@did-it[2].txt (ID = 2523)
8:54 PM: [removed][2].txt (ID = 2293)
8:54 PM: Found Spy Cookie: ru4 cookie
8:54 PM: tony@edge.ru4[1].txt (ID = 3269)
8:54 PM: Found Spy Cookie: empnads cookie
8:54 PM: tony@empnads[2].txt (ID = 5012)
8:54 PM: [removed][1].txt (ID = 2729)
8:54 PM: Found Spy Cookie: exitexchange cookie
8:54 PM: tony@exitexchange[2].txt (ID = 2633)
8:54 PM: Found Spy Cookie: expage cookie
8:54 PM: tony@expage[1].txt (ID = 2637)
8:54 PM: Found Spy Cookie: experclick cookie
8:54 PM: tony@experclick[2].txt (ID = 2639)
8:54 PM: Found Spy Cookie: findwhat cookie
8:54 PM: tony@findwhat[1].txt (ID = 2674)
8:54 PM: Found Spy Cookie: fortunecity cookie
8:54 PM: tony@fortunecity[2].txt (ID = 2686)
8:54 PM: Found Spy Cookie: gamespy cookie
8:54 PM: tony@gamespy[1].txt (ID = 2719)
8:54 PM: [removed][1].txt (ID = 2038)
8:54 PM: tony@go[2].txt (ID = 2728)
8:54 PM: Found Spy Cookie: starware.com cookie
8:54 PM: [removed][1].txt (ID = 3442)
8:54 PM: tony@hbmediapro[1].txt (ID = 2767)
8:54 PM: Found Spy Cookie: clickandtrack cookie
8:54 PM: [removed][1].txt (ID = 2397)
8:54 PM: Found Spy Cookie: homestore cookie
8:54 PM: tony@homestore[1].txt (ID = 2793)
8:54 PM: [removed][1].txt (ID = 3298)
8:54 PM: Found Spy Cookie: spywarelabs install cookie
8:54 PM: [removed][1].txt (ID = 3421)
8:54 PM: Found Spy Cookie: maxserving cookie
8:54 PM: tony@maxserving[1].txt (ID = 2966)
8:54 PM: Found Spy Cookie: metareward.com cookie
8:54 PM: tony@metareward[2].txt (ID = 2990)
8:54 PM: Found Spy Cookie: monstermarketplace cookie
8:54 PM: tony@monstermarketplace[1].txt (ID = 3006)
8:54 PM: Found Spy Cookie: 2o7.net cookie
8:54 PM: tony@msnportal.112.2o7[1].txt (ID = 1958)
8:54 PM: Found Spy Cookie: mygeek cookie
8:54 PM: tony@mygeek[1].txt (ID = 3041)
8:54 PM: [removed][1].txt (ID = 2038)
8:54 PM: Found Spy Cookie: nextag cookie
8:54 PM: tony@nextag[2].txt (ID = 5014)
8:54 PM: Found Spy Cookie: offeroptimizer cookie
8:54 PM: tony@offeroptimizer[1].txt (ID = 3087)
8:54 PM: [removed][1].txt (ID = 2038)
8:54 PM: tony@partygaming.122.2o7[1].txt (ID = 1958)
8:54 PM: Found Spy Cookie: partypoker cookie
8:54 PM: tony@partypoker[1].txt (ID = 3111)
8:54 PM: Found Spy Cookie: overture cookie
8:54 PM: [removed][1].txt (ID = 3106)
8:54 PM: Found Spy Cookie: pricegrabber cookie
8:54 PM: tony@pricegrabber[1].txt (ID = 3185)
8:54 PM: [removed][2].txt (ID = 2729)
8:54 PM: Found Spy Cookie: qksrv cookie
8:54 PM: tony@qksrv[2].txt (ID = 3213)
8:54 PM: Found Spy Cookie: questionmarket cookie
8:54 PM: tony@questionmarket[1].txt (ID = 3217)
8:54 PM: Found Spy Cookie: realmedia cookie
8:54 PM: tony@realmedia[2].txt (ID = 3235)
8:54 PM: Found Spy Cookie: valuead cookie
8:54 PM: [removed][2].txt (ID = 3627)
8:54 PM: tony@reunion[1].txt (ID = 3255)
8:54 PM: tony@revenue[1].txt (ID = 3257)
8:54 PM: Found Spy Cookie: rightmedia cookie
8:54 PM: tony@rightmedia[1].txt (ID = 3259)
8:54 PM: Found Spy Cookie: rn11 cookie
8:54 PM: tony@rn11[2].txt (ID = 3261)
8:54 PM: [removed][1].txt (ID = 2729)
8:54 PM: [removed][1].txt (ID = 2729)
8:54 PM: Found Spy Cookie: search123 cookie
8:54 PM: tony@search123[1].txt (ID = 3305)
8:54 PM: Found Spy Cookie: searchadnetwork cookie
8:54 PM: tony@searchadnetwork[2].txt (ID = 3311)
8:54 PM: [removed][2].txt (ID = 2729)
8:54 PM: Found Spy Cookie: spywarestormer cookie
8:54 PM: tony@spywarestormer[1].txt (ID = 3417)
8:54 PM: [removed][1].txt (ID = 2506)
8:54 PM: Found Spy Cookie: statstracking cookie
8:54 PM: tony@stats-tracking[1].txt (ID = 3453)
8:54 PM: Found Spy Cookie: tacoda cookie
8:54 PM: tony@tacoda[1].txt (ID = 6444)
8:54 PM: Found Spy Cookie: tracking cookie
8:54 PM: tony@tracking[1].txt (ID = 3571)
8:54 PM: Found Spy Cookie: trafficmp cookie
8:54 PM: tony@trafficmp[1].txt (ID = 3581)
8:54 PM: Found Spy Cookie: tribalfusion cookie
8:54 PM: tony@tribalfusion[1].txt (ID = 3589)
8:54 PM: Found Spy Cookie: tripod cookie
8:54 PM: tony@tripod[1].txt (ID = 3591)
8:54 PM: Found Spy Cookie: videodome cookie
8:54 PM: tony@videodome[1].txt (ID = 3638)
8:54 PM: Found Spy Cookie: webpower cookie
8:54 PM: tony@webpower[2].txt (ID = 3660)
8:54 PM: [removed][1].txt (ID = 2729)
8:54 PM: [removed][1].txt (ID = 3298)
8:54 PM: [removed][1].txt (ID = 3312)
8:54 PM: Found Spy Cookie: try games cookie
8:54 PM: [removed][1].txt (ID = 3594)
8:54 PM: tony@yieldmanager[2].txt (ID = 3749)
8:54 PM: Found Spy Cookie: adserver cookie
8:54 PM: [removed][1].txt (ID = 2142)
8:54 PM: tony@zedo[1].txt (ID = 3762)
8:54 PM: Found Spy Cookie: zenotecnico cookie
8:54 PM: tony@zenotecnico[1].txt (ID = 3858)
8:54 PM: Cookie Sweep Complete, Elapsed Time: 00:00:09
8:54 PM: Starting File Sweep
8:54 PM: c:\program files\eqadvice (3 subtraces) (ID = -2147454476)
8:54 PM: c:\program files\eqarticle (4 subtraces) (ID = -2147458679)
8:54 PM: c:\program files\fcadvice (2 subtraces) (ID = -2147454475)
8:56 PM: Found Adware: navexcel navhelper
8:56 PM: nhupdater.exe (ID = 70379)
8:57 PM: Found Adware: bookedspace
8:57 PM: rytspnuxn.ydt (ID = 164348)
8:58 PM: nhelper.htm (ID = 70374)
9:01 PM: bfgtoolbar_ins.exe (ID = 182622)
9:12 PM: Found Trojan Horse: trojan-dropper-mecorp
9:12 PM: nat2.exe (ID = 238169)
9:15 PM: runner.dll (ID = 257233)
9:16 PM: eqarticle.exe (ID = 238997)
9:16 PM: Found Adware: enbrowser
9:16 PM: tagasaurus.exe (ID = 244271)
9:17 PM: ntktnuwgj.dnc (ID = 164348)
9:17 PM: vhtrvwzowf.gsc (ID = 164416)
9:17 PM: rkvrqzbfz.ooi (ID = 158998)
9:17 PM: rogomggkxyk.gls (ID = 164350)
9:17 PM: eocijsw.hfh (ID = 159040)
9:17 PM: rukjgzu.aek (ID = 159013)
9:17 PM: rpnfvre.zye (ID = 159017)
9:17 PM: dkpirxil.vln (ID = 159027)
9:17 PM: eeogcmub.xpb (ID = 158991)
9:17 PM: fiisyyt.qwu (ID = 159005)
9:17 PM: ygdacxjxd.ztq (ID = 164392)
9:17 PM: settings.cfg (ID = 77495)
9:17 PM: mrtpzosloho.fgr (ID = 159030)
9:17 PM: drkbdtqsdm.onl (ID = 159004)
9:17 PM: afwjszak.idg (ID = 159003)
9:17 PM: mcphbkh.klz (ID = 158995)
9:17 PM: rbijxsum.gkh (ID = 159020)
9:17 PM: bgimivhw.zqe (ID = 159037)
9:17 PM: hqpxket.ztf (ID = 159016)
9:17 PM: ygfjeffo.dzc (ID = 158988)
9:18 PM: qycmhnhbcq.lut (ID = 164403)
9:18 PM: vgwmdqtqnmg.ktl (ID = 159047)
9:18 PM: magpxkampa.fcy (ID = 164351)
9:18 PM: zgohlpqajxj.nzi (ID = 159045)
9:18 PM: mftdgtpuiu.uqv (ID = 159060)
9:18 PM: gzxkerzvdpu.auo (ID = 158986)
9:18 PM: qlkrgjeyf.dzv (ID = 164361)
9:18 PM: ypqulqq.aup (ID = 164410)
9:18 PM: uuxbmwepan.jzc (ID = 164380)
9:18 PM: kbzehiameaz.mdj (ID = 159024)
9:18 PM: phitxwnq.jsb (ID = 159019)
9:18 PM: ckuerhspypz.xbr (ID = 159056)
9:18 PM: avicflsgth.bwn (ID = 159014)
9:18 PM: tfhgqgpvggo.imx (ID = 159058)
9:18 PM: bulzenzlu.onp (ID = 164404)
9:18 PM: wwxutixlj.vpg (ID = 159028)
9:18 PM: rgzoxurd.fkj (ID = 164372)
9:18 PM: rqfovbx.pji (ID = 159061)
9:18 PM: glpgdpn.yhj (ID = 159012)
9:18 PM: tbejvqisus.vcr (ID = 164377)
9:18 PM: emunesaqwvu.ktb (ID = 257809)
9:18 PM: moykxvdky.yfe (ID = 164354)
9:18 PM: cgatyxgtm.hpb (ID = 159025)
9:18 PM: oltqlfzy.oeo (ID = 164390)
9:18 PM: pxxndgdrebn.iar (ID = 164342)
9:18 PM: iyaudti.hhy (ID = 159026)
9:18 PM: yzuglyseuro.ebe (ID = 164415)
9:18 PM: jmzbftet.vuh (ID = 159018)
9:18 PM: kmmbzmv.bnh (ID = 158994)
9:18 PM: rpgmmkuh.oes (ID = 164408)
9:18 PM: ajryniuzt.efb (ID = 159031)
9:18 PM: dvrukuerdul.ubd (ID = 159035)
9:18 PM: jowyazwfl.vsl (ID = 158987)
9:18 PM: tsmuhpetw.jgn (ID = 159052)
9:18 PM: aiwteecgjf.vye (ID = 159038)
9:18 PM: tqsixywtwdt.ued (ID = 159001)
9:18 PM: abtjlka.yjr (ID = 159051)
9:18 PM: txetfmou.ske (ID = 164367)
9:18 PM: eeczggcrc.ycv (ID = 158990)
9:18 PM: vodcywtg.hny (ID = 164357)
9:18 PM: uzfgojrif.had (ID = 159029)
9:18 PM: notmuzzb.occ (ID = 159010)
9:18 PM: kkimcllj.kdm (ID = 159015)
9:18 PM: dikzkqeiihi.abx (ID = 159046)
9:18 PM: ysnvsiz.dyr (ID = 159059)
9:18 PM: ckayfqmu.vwa (ID = 159023)
9:18 PM: utvcqsx.pmd (ID = 158997)
9:18 PM: kbdyxdpxqx.acy (ID = 164344)
9:18 PM: uounysdi.jrw (ID = 164398)
9:18 PM: mjwycqijo.jyp (ID = 257808)
9:18 PM: lcfwawpxj.dbc (ID = 164373)
9:18 PM: contextualapp.exe (ID = 258286)
9:19 PM: Found Adware: virtualbouncer
9:19 PM: 89511931.exe (ID = 205451)
9:19 PM: bg8md.fyb (ID = 208796)
9:19 PM: transpd.exe (ID = 259587)
9:20 PM: equpdate.exe (ID = 238991)
9:20 PM: miniclipgameloader.dll (ID = 81258)
9:25 PM: yxifazjphs.avd (ID = 164416)
9:25 PM: hkmjewqfqb.sii (ID = 158998)
9:25 PM: avqaconytl.ara (ID = 159040)
9:25 PM: pclgrtbj.une (ID = 159013)
9:25 PM: psttfsewiqb.exg (ID = 159017)
9:25 PM: bkqbysjmel.fzp (ID = 164350)
9:25 PM: idhmrgrg.vpa (ID = 159027)
9:25 PM: bgdmulcfaao.tap (ID = 158991)
9:25 PM: aomzvgh.dni (ID = 164392)
9:25 PM: cvothjt.hri (ID = 159005)
9:25 PM: ekxhpzplmc.lva (ID = 159030)
9:25 PM: lwaiineks.nuq (ID = 159004)
9:25 PM: dcjorkkr.cwo (ID = 164357)
9:25 PM: nvlkgvcvroo.jyi (ID = 159003)
9:25 PM: kmhjypu.cwh (ID = 158995)
9:25 PM: uufgbabukqy.bhg (ID = 159020)
9:25 PM: eoyjrocskya.aag (ID = 159037)
9:25 PM: popcnhu.bcp (ID = 159016)
9:25 PM: jaeqewq.lyl (ID = 158988)
9:25 PM: vb1.exe (ID = 205462)
9:25 PM: s1ao.e.exe (ID = 213924)
9:25 PM: pixfcze.evd (ID = 159047)
9:25 PM: uxehephe.ujb (ID = 159045)
9:25 PM: uvymhgrn.zxz (ID = 164403)
9:25 PM: hfozaab.csw (ID = 159060)
9:25 PM: zgpasoixu.uhs (ID = 164380)
9:25 PM: kluicmodtde.fdf (ID = 158986)
9:25 PM: osjulsq.qtg (ID = 164351)
9:25 PM: bmthwtfgj.xte (ID = 164361)
9:25 PM: pomzgcjwa.wkp (ID = 164410)
9:25 PM: fphszmyter.dgi (ID = 159024)
9:25 PM: fqxuoxgumw.jql (ID = 159019)
9:25 PM: wffrkgg.hjq (ID = 164398)
9:25 PM: gpvmjdkjep.ceo (ID = 159056)
9:25 PM: zixvhijdoc.wkh (ID = 159014)
9:25 PM: lwxuyckcp.btg (ID = 159058)
9:25 PM: yzqnjqjvif.eoj (ID = 257808)
9:25 PM: cizcsrx.wrc (ID = 164404)
9:25 PM: wzarxuz.zjf (ID = 159028)
9:25 PM: pdldqafz.uux (ID = 164372)
9:25 PM: kgxbgat.ihg (ID = 164377)
9:25 PM: hrhcqyr.yeg (ID = 257809)
9:25 PM: drmzrdyrdl.epp (ID = 159061)
9:25 PM: johbknrpk.num (ID = 164354)
9:25 PM: rgedhqjplyp.lbg (ID = 159012)
9:25 PM: elctezoqalf.zii (ID = 159025)
9:25 PM: fmwfmyhxie.vin (ID = 164390)
9:25 PM: ijxgdqdofk.wuj (ID = 164342)
9:25 PM: ealmpkayjej.oqj (ID = 159026)
9:25 PM: gjaiimfa.dgr (ID = 164415)
9:25 PM: tlvlcxgw.hga (ID = 159018)
9:25 PM: ouhktcv.cyb (ID = 164373)
9:25 PM: nkycjrlss.wth (ID = 158994)
9:25 PM: qhpjilr.egp (ID = 164408)
9:25 PM: qxwbbbapwc.nnf (ID = 159031)
9:25 PM: jtocfbptcv.mmq (ID = 159035)
9:25 PM: ehixszgga.lfl (ID = 158987)
9:25 PM: nqeetygdmh.lje (ID = 159052)
9:25 PM: engqajjoui.kym (ID = 159038)
9:25 PM: olrywmvo.bcu (ID = 159001)
9:25 PM: nxafdclb.mou (ID = 159051)
9:25 PM: mlwlpnfz.dkd (ID = 158990)
9:25 PM: trgcgcmoh.gab (ID = 164367)
9:25 PM: ieefbyez.xiq (ID = 159029)
9:25 PM: hdzgcivs.srf (ID = 159010)
9:25 PM: kiitakxc.tmt (ID = 159015)
9:25 PM: hyzlqysobps.ilg (ID = 159046)
9:25 PM: bmjtnzmrm.gpf (ID = 159059)
9:25 PM: vygsimlcghe.hhq (ID = 159023)
9:25 PM: mfmiwlta.udj (ID = 164344)
9:25 PM: rlbjqxesme.qjv (ID = 158997)
9:25 PM: zeno.lnk (ID = 146127)
9:26 PM: 8951193.ini (ID = 212956)
9:27 PM: File Sweep Complete, Elapsed Time: 00:33:00
9:27 PM: Full Sweep has completed. Elapsed time 00:37:00
9:27 PM: Traces Found: 733
9:37 PM: Removal process initiated
9:38 PM: Quarantining All Traces: fullcontext
9:38 PM: fullcontext is in use. It will be removed on reboot.
9:38 PM: runner.dll is in use. It will be removed on reboot.
9:38 PM: eqarticle.exe is in use. It will be removed on reboot.
9:38 PM: Quarantining All Traces: trojan-downloader-exfol
9:38 PM: Quarantining All Traces: enbrowser
9:38 PM: Quarantining All Traces: marketscore
9:38 PM: Quarantining All Traces: quicklink search toolbar
9:38 PM: quicklink search toolbar is in use. It will be removed on reboot.
9:38 PM: bg8md.fyb is in use. It will be removed on reboot.
9:38 PM: Quarantining All Traces: trojan_backdoor_retro64
9:38 PM: Quarantining All Traces: trojan-dropper-mecorp
9:38 PM: Quarantining All Traces: big fish games toolbar
9:38 PM: Quarantining All Traces: bookedspace
9:38 PM: Quarantining All Traces: navexcel navhelper
9:38 PM: Quarantining All Traces: superbar
9:38 PM: Quarantining All Traces: virtualbouncer
9:38 PM: Quarantining All Traces: zenosearchassistant
9:38 PM: Quarantining All Traces: 2o7.net cookie
9:38 PM: Quarantining All Traces: 3 cookie
9:38 PM: Quarantining All Traces: 412 cookie
9:38 PM: Quarantining All Traces: 447 cookie
9:38 PM: Quarantining All Traces: 64.62.232 cookie
9:38 PM: Quarantining All Traces: 735 cookie
9:38 PM: Quarantining All Traces: 888 cookie
9:38 PM: Quarantining All Traces: about cookie
9:38 PM: Quarantining All Traces: addynamix cookie
9:38 PM: Quarantining All Traces: adecn cookie
9:38 PM: Quarantining All Traces: adknowledge cookie
9:38 PM: Quarantining All Traces: adlegend cookie
9:38 PM: Quarantining All Traces: adprofile cookie
9:38 PM: Quarantining All Traces: adrevolver cookie
9:38 PM: Quarantining All Traces: adserver cookie
9:38 PM: Quarantining All Traces: apmebf cookie
9:38 PM: Quarantining All Traces: ask cookie
9:38 PM: Quarantining All Traces: atwola cookie
9:38 PM: Quarantining All Traces: azjmp cookie
9:38 PM: Quarantining All Traces: banner cookie
9:38 PM: Quarantining All Traces: banners cookie
9:38 PM: Quarantining All Traces: belnk cookie
9:38 PM: Quarantining All Traces: bizrate cookie
9:38 PM: Quarantining All Traces: bluestreak cookie
9:38 PM: Quarantining All Traces: casalemedia cookie
9:38 PM: Quarantining All Traces: cassava cookie
9:38 PM: Quarantining All Traces: cc214142 cookie
9:38 PM: Quarantining All Traces: classmates cookie
9:38 PM: Quarantining All Traces: clickads cookie
9:38 PM: Quarantining All Traces: clickandtrack cookie
9:38 PM: Quarantining All Traces: dealtime cookie
9:38 PM: Quarantining All Traces: did-it cookie
9:38 PM: Quarantining All Traces: empnads cookie
9:38 PM: Quarantining All Traces: enhance cookie
9:38 PM: Quarantining All Traces: exitexchange cookie
9:38 PM: Quarantining All Traces: expage cookie
9:38 PM: Quarantining All Traces: experclick cookie
9:38 PM: Quarantining All Traces: falkag cookie
9:38 PM: Quarantining All Traces: findwhat cookie
9:38 PM: Quarantining All Traces: fortunecity cookie
9:38 PM: Quarantining All Traces: gamespy cookie
9:38 PM: Quarantining All Traces: go.com cookie
9:38 PM: Quarantining All Traces: hbmediapro cookie
9:38 PM: Quarantining All Traces: homestore cookie
9:38 PM: Quarantining All Traces: maxserving cookie
9:38 PM: Quarantining All Traces: megago cookie
9:38 PM: Quarantining All Traces: metareward.com cookie
9:38 PM: Quarantining All Traces: monstermarketplace cookie
9:38 PM: Quarantining All Traces: mygeek cookie
9:38 PM: Quarantining All Traces: nextag cookie
9:38 PM: Quarantining All Traces: offeroptimizer cookie
9:38 PM: Quarantining All Traces: overture cookie
9:38 PM: Quarantining All Traces: partypoker cookie
9:38 PM: Quarantining All Traces: precisead cookie
9:38 PM: Quarantining All Traces: pricegrabber cookie
9:38 PM: Quarantining All Traces: qksrv cookie
9:38 PM: Quarantining All Traces: questionmarket cookie
9:38 PM: Quarantining All Traces: realmedia cookie
9:38 PM: Quarantining All Traces: reunion cookie
9:38 PM: Quarantining All Traces: revenue.net cookie
9:38 PM: Quarantining All Traces: rightmedia cookie
9:38 PM: Quarantining All Traces: rn11 cookie
9:38 PM: Quarantining All Traces: ru4 cookie
9:38 PM: Quarantining All Traces: screensavers.com cookie
9:38 PM: Quarantining All Traces: search123 cookie
9:38 PM: Quarantining All Traces: searchadnetwork cookie
9:38 PM: Quarantining All Traces: specificclick.com cookie
9:38 PM: Quarantining All Traces: spywarelabs install cookie
9:38 PM: Quarantining All Traces: spywarestormer cookie
9:38 PM: Quarantining All Traces: starware.com cookie
9:38 PM: Quarantining All Traces: statstracking cookie
9:38 PM: Quarantining All Traces: tacoda cookie
9:38 PM: Quarantining All Traces: tickle cookie
9:38 PM: Quarantining All Traces: tracking cookie
9:38 PM: Quarantining All Traces: trafficmp cookie
9:38 PM: Quarantining All Traces: tribalfusion cookie
9:38 PM: Quarantining All Traces: tripod cookie
9:38 PM: Quarantining All Traces: try games cookie
9:38 PM: Quarantining All Traces: valuead cookie
9:38 PM: Quarantining All Traces: videodome cookie
9:38 PM: Quarantining All Traces: webpower cookie
9:38 PM: Quarantining All Traces: websponsors cookie
9:38 PM: Quarantining All Traces: yieldmanager cookie
9:38 PM: Quarantining All Traces: zedo cookie
9:38 PM: Quarantining All Traces: zenotecnico cookie
9:38 PM: Warning: Timed out waiting for explorer.exe
9:38 PM: Warning: Launched explorer.exe
9:38 PM: Warning: Quarantine process could not restart Explorer.
9:39 PM: Preparing to restart your computer. Please wait…
9:39 PM: Removal process completed. Elapsed time 00:01:34
********
8:46 PM: | Start of Session, Saturday, April 01, 2006 |
8:46 PM: Spy Sweeper started
8:47 PM: Your spyware definitions have been updated.
8:50 PM: | End of Session, Saturday, April 01, 2006 |
I followed your instructions and i'm still getting popups. I even get them when i disconnect from the internet. I have one other computer networked with this one but it is not having the popup problems but is slowed down when using the internet. I use Mozilla browser most of the time. The popups are using IE.
Thanks for taking the time to help, as i can see alot of people are having problems.
Tony