This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can someone please look at the following logs for my pc and laptop. Both running real slow, particulary on start up.

LAPTOP
Logfile of HijackThis v1.99.1
Scan saved at 8:05:54 PM, on 29/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSN Explorer] C:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSN Explorer] C:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

PC
Logfile of HijackThis v1.99.1
Scan saved at 8:35:28 PM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Edmund Schwerdt\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ap.dell.com/content/default.as…;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ap.dell.com/content/default.as…;l=en&s=gen
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Download and install Ewido on both PC's. Then scan and post the report here.
Instructions and download link can be found here.

Also post a new hijackthis logs.
Hi,

Can you please look at my hijack logs (pc and laptop) run after doing the ewido scan. (also attached)

Both running real slow.

Logfile of HijackThis v1.99.1 LAPTOP
Scan saved at 10:21:39 PM, on 14/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSN Explorer] C:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSN Explorer] C:\windows\system32\drivers\helpsys\msnexplorer.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


Laptop ewido scan:
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:01:33 PM 8/09/2006

+ Scan result:



C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.


::Report end


Logfile of HijackThis v1.99.1 PC
Scan saved at 10:57:18 PM, on 9/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Edmund Schwerdt\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ap.dell.com/content/default.as…;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ap.dell.com/content/default.as…;l=en&s=gen
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:\Windows\SVCHOS~2.DLL (file missing)
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra 'Tools' menuitem: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - C:\Program Files\Noble Poker\casino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

PC Ewido Reportewido anti-spyware - Scan Report
———————————————————

+ Created at: 10:55:58 PM 9/14/2006

+ Scan result:



C:\Documents and Settings\Edmund Schwerdt\My Documents\Downloads\Programs\SetupPoker.exe -> Adware.Casino : No action taken.
C:\Documents and Settings\Edmund Schwerdt\My Documents\Downloads\Programs\SetupPoker_2.exe -> Adware.Casino : No action taken.
C:\WINDOWS\Club Dice Poker setup.exe -> Adware.Casino : No action taken.
C:\WINDOWS\Noble Poker setup.exe -> Adware.Casino : No action taken.
C:\WINDOWS\Poker Ocean setup.exe -> Adware.Casino : No action taken.
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UZ6Z9QIY\FreeMyEmoticons[1].exe/MyEmoticons_WhenUSaveNow_Installer.exe -> Adware.SaveNow : No action taken.
C:\Program Files\whInstall -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\Sporder.dll -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\license.txt -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\whInstaller.ini -> Adware.Webhancer : No action taken.
C:\WINDOWS\system32\regm64.dll -> Logger.KeyLogger.bp : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\BIDX.exe -> Logger.KeyLogger.cc : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\DFQH.exe -> Logger.KeyLogger.cc : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\PAFF.exe -> Logger.KeyLogger.cc : No action taken.
C:\WINDOWS\system32\msvchost.exe -> Logger.KeyLogger.cc : No action taken.
C:\WINDOWS\system32\ssvchost.exe -> Logger.KeyLogger.cc : No action taken.
HKLM\SOFTWARE\Classes\PK.IE -> Logger.PerfectKeylogger : No action taken.
HKLM\SOFTWARE\Classes\PK.IE.1 -> Logger.PerfectKeylogger : No action taken.
HKLM\SOFTWARE\Classes\PK.IE\CLSID -> Logger.PerfectKeylogger : No action taken.
HKLM\SOFTWARE\Classes\PK.IE\CurVer -> Logger.PerfectKeylogger : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP207\A0027474.dll -> Logger.Perfloger.i : No action taken.
C:\WINDOWS\__delete_on_reboot__S_V_C_H_O_S_~_2_._D_L_L_ -> Logger.Perfloger.i : No action taken.
[3596] C:\Windows\SVCHOS~2.DLL -> Logger.Perfloger.i : No action taken.
C:\WINDOWS\rinst.exe -> Logger.Perfloger.l : No action taken.
C:\WINDOWS\svchostr.exe -> Logger.Perfloger.l : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP207\A0027473.exe -> Not-A-Virus.Monitor.Win32.Perflogger.ad : No action taken.
C:\WINDOWS\__delete_on_reboot__s_v_c_h_o_s_t_._e_x_e_ -> Not-A-Virus.Monitor.Win32.Perflogger.ad : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP207\A0027472.dll -> Not-A-Virus.Monitor.Win32.Perflogger.al : No action taken.
C:\WINDOWS\__delete_on_reboot__s_v_c_h_o_s_t_h_k_._d_l_l_ -> Not-A-Virus.Monitor.Win32.Perflogger.al : No action taken.
:mozilla.905:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.105:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.134:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.245:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.309:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.363:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.364:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.426:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.850:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.851:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.852:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.853:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.854:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.855:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.858:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.859:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.860:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.864:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.868:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.869:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.871:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.872:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.878:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.884:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.887:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.888:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.902:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.943:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.957:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.989:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Dylan\Local Settings\Temp\Cookies\dylan@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Cookies\edmund schwerdt@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\Cookies\edmund schwerdt@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.978:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.979:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.450:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Cookies\edmund schwerdt@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.907:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Dylan\Local Settings\Temp\Cookies\dylan@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Cookies\edmund schwerdt@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\Cookies\edmund schwerdt@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.337:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.945:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.921:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.929:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.930:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.931:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.934:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.935:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.877:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
:mozilla.977:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
:mozilla.707:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.637:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Edmund Schwerdt\Local Settings\Temp\Cookies\edmund schwerdt@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.572:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.574:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.575:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.576:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.577:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.578:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.579:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.580:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.583:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.585:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.586:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.587:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.588:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.589:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.590:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.591:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.592:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.593:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.594:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.595:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.597:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.598:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.599:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.600:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.601:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.602:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.603:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.604:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.605:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.606:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.608:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.609:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.610:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.611:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.612:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.613:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.614:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.619:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.622:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.624:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.625:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.626:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.628:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.629:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.634:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.635:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.636:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.638:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.639:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.640:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.644:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.645:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.646:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.647:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.648:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.649:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.650:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.651:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.652:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.654:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.656:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.657:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.658:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.659:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.660:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.661:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.662:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.663:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.666:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.667:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.668:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.670:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.671:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.672:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.675:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.676:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.677:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.687:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.688:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.689:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.690:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.691:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.692:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.693:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.694:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.695:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.697:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.698:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.699:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.700:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.701:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.702:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.703:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.704:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.705:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.706:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.708:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.709:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.710:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.711:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.714:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.715:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.716:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.717:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox\Profiles\io4jl72v.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.718:C:\Documents and Settings\Edmund Schwerdt\Application Data\Mozilla\Firefox&
lets work on one at a time, starting with the PC

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:\Windows\SVCHOS~2.DLL (file missing)
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab


Reboot in safe mode, instructions here.
Some of these files my have hidden atributes.
Click Here Should you need instructions for Showing hidden files and folders in Windows.
Once in safe mode, Click start / then my computer / local disk then follow the process tree.
Or using Windows Explorer, locate the first file right click then select delete.

Delete the following folder(s) listed in bold.
C:\Program Files\MyWaySA

Download and run - ATF Cleaner instructions here.

Run ewido again this time deleteing all that is found.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI