This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Baseline on friends computer Help Please!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Below is the HJT log of my buddy's computer. It has four users and is an XP SP2 machine. I have been trying to get rid of all the nasty's for a week to no avail. As far as I know he did not have any antivirus on but had Spybot and Adaware but had not updated in a long time. I humbly ask the experts here for their help.

Logfile of HijackThis v1.99.1
Scan saved at 9:36:33 AM, on 9/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\lexbces.exe
C:\WINDOWS\System32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sru.edu/
R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {0B6899B6-1564-43e0-BD93-F7CF930A5E5C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O15 - Trusted Zone: *.aflashcounter.com
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/games/clients/y/dct4_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! Pinochle - http://download.games.yahoo.com/games/clients/y/ut2_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potg_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1158510935546
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\System32\lexbces.exe
O23 - Service: MSMPSVC - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe" -n 4 (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
hi DougNash, you have spybot, ewido,windows defender. dont see anything to be worried about in the log. you can have hjt fix these though: R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: (no name) - {0B6899B6-1564-43e0-BD93-F7CF930A5E5C} - (no file) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O15 - Trusted Zone: *.aflashcounter.com O15 - Trusted Zone: *.elitemediagroup.net shelf life
OK I have to add a new log and I also forgot to add the Ewido scan log also. I added AVG Free and Sygate Firewall also. There is a problem but I cannot remember the name of it as of yet. I will have to switch over computers and post both of the logs. I only make this post to bump it up so that I am not on my network with an infected machine very long I apologize to all.
OK Here is my new HijackThis Log and my Ewido log also

Logfile of HijackThis v1.99.1
Scan saved at 3:37:26 PM, on 9/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lexbces.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\LEXPPS.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Hijackthis\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sru.edu/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/games/clients/y/dct4_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! Pinochle - http://download.games.yahoo.com/games/clients/y/ut2_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potg_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1158510935546
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\System32\lexbces.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 2:35:57 AM 9/21/2006

+ Scan result:



C:\Program Files\Microsoft AntiSpyware\Quarantine\9C34A556-4866-454E-AAC1-982F5C\10D541DB-9F1C-4D23-ABB7-2F0006 -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\thiselt.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\c41bUs.dll/bi.dll -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\c41bUs.dll/preInsBI.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\uxsxkuog.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\Xcite2.exe -> Adware.F1Organizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\Browser -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\Faceplate -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\History -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\Resources -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\Stations -> Adware.HiWire : Cleaned with backup (quarantined).
HKU\S-1-5-21-790525478-299502267-725345543-500\Software\Hiwire\MusicMatch\WebUpdate -> Adware.HiWire : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\WINDOWS\876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ScreensaversInstaller.Installer -> Adware.Screensavers : Error during cleaning.
HKLM\SOFTWARE\Classes\ScreensaversInstaller.Installer.1 -> Adware.Screensavers : Error during cleaning.
HKLM\SOFTWARE\Classes\ScreensaversInstaller.Sinstaller -> Adware.Screensavers : Error during cleaning.
HKLM\SOFTWARE\Classes\ScreensaversInstaller.Sinstaller.1 -> Adware.Screensavers : Error during cleaning.
C:\WINDOWS\SYSTEM32\nsb1D3.dll -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Documents and Settings\Shannon Baker\My Documents\Oregon Trail\OregonTrail-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\MediaGateway.exe -> Adware.WinAD : Cleaned with backup (quarantined).
C:\WINDOWS\uamfqawur.dll -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\WINDOWS\idlemg.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Program Files\Accessories\mezokes.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\WINDOWS\ac3_0002.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\Documents and Settings\Shannon Baker\Local Settings\Temporary Internet Files\Content.IE5\UBADML4P\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Program Files\Common Files\pohow.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\Messenger\mefetoj.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\tm54589.exe -> Logger.Delf.or : Cleaned with backup (quarantined).
C:\Documents and Settings\Shannon Baker\Local Settings\Temporary Internet Files\Content.IE5\6T4N6B0N\xp-cydoor-728[1].swf -> Not-A-Virus.Hoax.SWF.Alerter.a : Ignored.
:mozilla.72:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.73:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.74:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.75:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.76:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.77:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.86:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@cnn.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@microsofteup.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@partygaming.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@smoothcorp.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@tgn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@aavalue[3].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Adtrak : Cleaned.
:mozilla.24:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.25:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.26:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.27:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.28:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.13:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.94:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][3].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][4].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@burstnet[5].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon baker@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon [removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.10:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.11:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.12:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.9:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@cliks[1].txt -> TrackingCookie.Cliks : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@cliks[1].txt -> TrackingCookie.Cliks : Cleaned.
:mozilla.91:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.92:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.71:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@cpvfeed[4].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon baker@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.19:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.58:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.65:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon baker@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned.
:mozilla.23:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed]-targeting[1].txt -> TrackingCookie.Mx-targeting : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed]-targeting[1].txt -> TrackingCookie.Mx-targeting : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.29:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.30:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.31:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@edge.ru4[3].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned.
:mozilla.102:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.103:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.104:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.105:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@serving-sys[4].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@shopathomeselect[2].txt -> TrackingCookie.Shopathomeselect : Cleaned.
:mozilla.95:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][4].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon baker@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.63:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.64:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.93:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@webstat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy baker@webstat[3].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed]-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.18:C:\Documents and Settings\Shannon Baker\Application Data\Mozilla\Firefox\Profiles\fi8lp01c.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jeremy Baker\Cookies\jeremy [removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon [removed][4].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Cookies\shannon baker@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shannon Baker\Local Settings\Temp\Cookies\shannon [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Common Files\Yazzle1119OinAdmin.exe -> Trojan.Scapur.k : Cleaned with backup (quarantined).
C:\WINDOWS\uni_ehhhh.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).


::Report end

I also have to have Ewido remove Adware.Screensavers. I tried but it will not remove it even in Safe Mode. When I installed AVG it found and healed Trojan Downloader.Zlob.BZ I am not sure what that is but it said it was cleaned. I am also having trouble getting CCleaner remove all of the issue in the Registry. I thank you for this site and for any help.
No not in the Add Remove Proram list. Other than that coming up in Ewido it works perfectly well maybe not perfect but better by millions than it was working. I still want to add Spyware Guard though.
hi DougNash, try a boot into safe mode, then run ewido. to reach safe mode tap the f8 key during a computer restart, chose the first option from the list: safe mode. after ewido runs reboot normally.
I have done the safe mode running of Ewido it doesn't remove the Adware. I tried a safe mode running of all the programs I have on the machine and nothing removes it. I can say that the Trojan has not made another appearance though. I like that and so shall my friend. I am afraid to return his machine if there is a possibility of another problem appearing right after it is returned.
hi DougNash, normally ewido does a great job of cleaning up. iam sure those are just harmless leftover registry entries that for whatever reason ewido is not cleaning up. we could try a reg fix, but that may not work either. shelf life
Good Enough for me I guess. I will return the machine now and keep an eye on this site for any other ideas. I have noticed a marked improvement on the performance of this machine. Thanks and God Bless you all here for your help. I have three other machines that I will run a Hijack This on and see if all is well if that is alright with you all?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI