UNSOLVED

Niles3366

updated

20 years ago

N

Niles3366

20 Posts

0

1667

September 18th, 2006 20:00

Help With hijackthis please

Hello, my wife has done quite a bit of downloading and now we have a lot of problems with windows defender popping up SEP threats.  I do not have any problems with my laptop, so I am hoping someone could please help me.  Here is the hijackthis log
 
Logfile of HijackThis v1.99.1
Scan saved at 4:06:50 PM, on 9/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\windows\system32\buK.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\w?nspool.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\SYSTEM32\buK.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDsHkhWqtO3evZFfl7nIWD0usKoOG48ThBP49/3Ubc9FaaSxbtidWnb28jA+mN5H42e+DXWxXH3TjwMFFn5Bo7JOESsRkh191tpfoQwqwMXbg+RYouPOU7N3GPpqioiESbx4ndvn2LzJpglaaNxD1ZsPpeyb3VvvsOS13lRY1OszEX6w5SR+HzM2KbR/Zj/mKm19vnq/yuo7E=
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {39DA357D-9263-52C7-8604-165504F7786B} - C:\WINDOWS\system32\hikbf.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Starware - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\Program Files\Starware\bin\Starware.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [buK.exe] C:\windows\system32\buK.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Hzvlv] C:\WINDOWS\system32\w?nspool.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: HPAiODevice(hp psc 900 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099361013330
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http://www.mindavenue.com/Downloads/AXELPlayerAX_Win32.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121049800390
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.0/installer.exe
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://neo2.agribank.com/dana-cached/setup/JuniperSetup.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
  • Bugbatter

    4 Apprentice

    20487 Posts

    738

    0

    Posted September 20th, 2006 19:00

    Hi, Niles,

    Your wife has accumulated quite a collection there.
    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.

    You will now be presented with a screen.
    Press the Save button, and a notepad will open with the contents of that file.
    Simply copy and paste the contents of that notepad into a reply in this topic along with a fresh HijackThis log so we can start cleaning.
    Thanks. :)
  • Niles3366

    20 Posts

    738

    0

    Posted September 20th, 2006 23:00

    Here is new HJT
     
    Logfile of HijackThis v1.99.1
    Scan saved at 7:03:13 PM, on 9/20/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
    C:\windows\system32\buK.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM32\buK.exe
    C:\WINDOWS\system32\w?nspool.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
    C:\WINDOWS\system32\hpoipm07.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Hijackthis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDsHkhWqtO3evZFfl7nIWD0usKoOG48ThBP49/3Ubc9FaaSxbtidWnb28jA+mN5H42e+DXWxXH3TjwMFFn5Bo7JOESsRkh191tpfoQwqwMXbg+RYouPOU7N3GPpqioiESbx4ndvn2LzJpglaaNxD1ZsPpeyb3VvvsOS13lRY1OszEX6w5SR+HzM2KbR/Zj/mKm19vnq/yuo7E=
    R3 - Default URLSearchHook is missing
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: (no name) - {39DA357D-9263-52C7-8604-165504F7786B} - C:\WINDOWS\system32\hikbf.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: Starware - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\Program Files\Starware\bin\Starware.dll
    O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [buK.exe] C:\windows\system32\buK.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [Hzvlv] C:\WINDOWS\system32\w?nspool.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HPAiODevice(hp psc 900 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099361013330
    O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http://www.mindavenue.com/Downloads/AXELPlayerAX_Win32.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121049800390
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/ftp.coupons.com/v3123/cpbrkpie.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.0/installer.exe
    O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
    O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://neo2.agribank.com/dana-cached/setup/JuniperSetup.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
  • Niles3366

    20 Posts

    738

    0

    Posted September 20th, 2006 23:00

    Looks like I might have to seperate these files because of space.  Here is uninstall
     
    3D Groove Playback Engine
    5 Spots II (remove only)
    Adobe Download Manager 2.0 (Remove Only)
    Adobe Reader 7.0.5 Language Support
    Adobe Reader 7.0.8
    Adobe® Photoshop® Album Starter Edition 3.0
    Adventures of Bleeposaurus (remove only)
    BCM V.92 56K Modem
    Bejeweled 2
    Blues Room (remove only)
    Care Bears Lets Have a Ball (remove only)
    Classic PhoneTools
    Creative MediaSource
    Cubis Gold 2
    DAO
    Deerfield Valley
    Dell Digital Jukebox Driver
    Dell Media Experience
    Dell Picture Studio - Dell Image Expert
    Dell ResourceCD
    Dell Solution Center
    Dell Support 5.0.0 (766)
    DellConnect
    Diego`s Wolf Pup Rescue (remove only)
    DMVlite
    Does It Belong
    Dora Lost City
    Dora the Explorer 3D Pyramid Adventure (remove only)
    DS21Patch
    DVDSentry
    eSyndicate
    Google Toolbar for Internet Explorer
    HighMAT Extension to Microsoft Windows XP CD Writing Wizard
    HijackThis 1.99.1
    HP Photo Printing Software
    hp psc 900 series
    HP Share-to-Web
    Intel A/V Codecs V2.0
    Intel(R) PRO Network Adapters and Drivers
    Intel(R) PROSet
    ItsDeductible Express
    Java 2 Runtime Environment, SE v1.4.2
    Joes 3-D Scavenger Hunt (remove only)
    JumpStart Spelling
    Juniper Networks Secure Application Manager
    LiveUpdate 2.6 (Symantec Corporation)
    Logitech MouseWare 9.77
    Macromedia Flash Player 8
    Macromedia Shockwave Player
    Magic Ball 2 (remove only)
    Memory Stick Formatter
    Mickey Mouse Preschool
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB886903)
    Microsoft Baseline Security Analyzer 1.2.1
    Microsoft Encarta Encyclopedia Standard 2003
    Microsoft Money 2003
    Microsoft Money 2003 System Pack
    Microsoft Office Professional Edition 2003
    Microsoft Office XP Media Content
    Microsoft Picture It! Photo 7.0
    Microsoft Streets and Trips 2002
    Microsoft Windows Journal Viewer
    Microsoft Works 2003 Setup Launcher
    Microsoft Works 7.0
    Microsoft Works Suite Add-in for Microsoft Word
    Modem Helper
    MSN Music Assistant
    Musicmatch® Jukebox
    Nick Aracde Toolbar
    Norton WMI Update
    NVIDIA Display Driver
    NVIDIA Windows 2000/XP Display Drivers
    Paint Shop Pro 7 Anniversary Edition
    PowerDVD
    QuickTime
    RealPlayer
    Same or Different
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB903235)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911280)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    SEP
    Sound Blaster Audigy 2
    Stanley Wild for Sharks
    Starware 3.3.2.0
    Symantec AntiVirus
    Symantec Network Driver Update
    TONKA Search & Rescue 2
    Transition Math K-1
    Turbo Lister 2
    TurboTax Deluxe 2003
    TurboTax Deluxe 2004
    TurboTax Deluxe 2005
    TurboTax ItsDeductible 2005
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Viewpoint Manager (Remove Only)
    Viewpoint Toolbar V35 (Remove Only)
    Web Browser Component Manager
    WexTech AnswerWorks
    Windows Defender
    Windows Defender Signatures
    Windows Genuine Advantage v1.3.0254.0
    Windows Installer 3.1 (KB893803)
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB834707
    Windows XP Hotfix - KB867282
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890047
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB890923
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Windows XP Hotfix - KB893086
    Windows XP Service Pack 2
    Winnie the Pooh Preschool
    Yahoo! Toolbar
    Zango Toolbar
    Zoboomafoo Animal Alphabet(TM)
  • Bugbatter

    4 Apprentice

    20487 Posts

    738

    0

    Posted September 21st, 2006 01:00

    Thanks.

    We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.

    * Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
    * Click on Tools, General Settings
    * Under Real-time protection options, unselect the Turn on real-time protection check box
    * Click Save

    After all of the fixes are complete it is very important that you enable Real-time Protection again.

    Let's remove the Zango toolbar using Add/Remove Programs.

    http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096812

    Delete the Zango folder here:
    C:\Program Files\ Zango Programs --FOLDER


    Reboot and download and run this uninstaller:
    http://www.outerinfo.com/OiUninstaller.exe

    Tutorial for the uninstaller if needed

    Reboot

    Download ewido anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program

    1. Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right click on ewido in the system tray and uncheck "Start with Windows".
    3. Go to Start > Run and type: services.msc
    4. Press "OK".
    5. In Services, click the "Extended tab" and scroll down the list to find ewido anti-spyware 4.0 guard.
    6. When you find the guard service, double-click on it.
    7. In the Properties Window > General Tab that opens, click the "Stop" button.
    8. From the drop-down menu next to "Startup Type", click on "Manual".
    9. Now click "Apply", then "OK" and close the Services window
    10. Once the setup is complete you will need run ewido and update the definition files.
    11. On the main screen select the icon "Update". Tthen select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
      • If you are having problems with the updater, manually update with the Ewido Full database installer from here.
      • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
      • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
      • Under "Reports"
        • Select "Automatically generate report after every scan"
        • Un-Select "Only if threats were found"
        • Close Ewido anti-spyware, Do Not run a scan just yet, we will shortly.
          1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
          2. IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
          3. Launch ewido-anti-spyware by double-clicking the icon on your desktop.
          4. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
          5. ewido will now begin the scanning process, be patient this may take a little time.
          6. Once the scan is complete do the following:
          7. If you have any infections you will prompted, then select "Apply all actions"
          8. Next select the "Reports" icon at the top.
          9. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
          10. Close ewido and reboot your system back into Normal Mode.

          11. Clean out your Temporary Internet files. Proceed like this:
            • Quit Internet Explorer and quit any instances of Windows Explorer.
            • Click Start, click Control Panel, and then double-click Internet Options.
            • On the General tab, click Delete Files under Temporary Internet Files.
            • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
            • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
            • Click Apply then OK.

              Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin

              Please reboot and post a fresh HJT log and the log from Ewido.
              After that, we'll clean what is left.

        Message Edited by Bugbatter on 09-20-2006 09:22 PM

      • Niles3366

        20 Posts

        593

        0

        Posted September 21st, 2006 03:00

        C:\Documents and Settings\Default\Local Settings\Temp\update_1.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1080\A0113842.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\WINDOWS\SYSTEM32\ab3FSE.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\3B3228EA-8D7A-4078-B56E-AAE3A5\8F5F44A6-5F5F-4A35-8484-7A9712 -> Downloader.Apropo.ab : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\4DC98390-2B7F-4650-BD3F-C3A1AD\2BC72515-DDE0-470E-9B9E-AA2820 -> Downloader.Braidupdate.d : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\F21B95EB-D90C-403C-87CC-7951D0\EEB94DA1-D525-4AC3-A356-C2D373 -> Downloader.Braidupdate.d : Cleaned with backup (quarantined).
        C:\incredifind.exe -> Downloader.Keenval : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\790E9A9D-D6E4-43D8-9BC7-222EE0\0040FE0E-953D-4B51-9F35-BA0A6D -> Downloader.Small.asf : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\i13E.tmp -> Downloader.Totavel.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\D70CD7A9-02B9-44B7-B7B9-4591AC\BA04AB88-03CA-43A1-AFEB-E39553 -> Hijacker.Agent.dh : Cleaned with backup (quarantined).
        C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Temporary Internet Files\Content.IE5\9VVZDPGM\jsmain[2].js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Temporary Internet Files\Content.IE5\V2SFV98T\jsmain[1].js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@adc.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@rotator.dex.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@thunderbolt.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@adtrak[1].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@www.adtrak[2].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@www.casinotropez[2].txt -> TrackingCookie.Casinotropez : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@centrport[2].txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@clickagents[2].txt -> TrackingCookie.Clickagents : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@com[2].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@commission-junction[1].txt -> TrackingCookie.Commission-junction : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjl4cgcjagog-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjl4widpkaog-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmykhajwfog-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmywlczklow-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnyoicjabqq-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnyolajwapa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4ogajekqqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiwmajahowqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkogjd5keoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoslcjsgow2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoupdjocoaidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyogajkfqamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkywoazagowsdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wfliahdjcapg2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4andjwlpqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4apazclowydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4coajafpa2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4whd5alpgidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4wpdzaaqaqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoclcjalpqydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoelajmdoaidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoemajglpq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkokmc5ckowwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyamc5sgqaydj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkygiajiapwidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyupc5iaow6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4ghdjcfpaqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4upcpccpaudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlisjdjwhpgmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlismd5eapwqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliwgdzghpa6dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloclajghpw2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlocncpwepgqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloegcjihoqydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlycgd5aeqasdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyoodjabpq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyqoc5akpaidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiumdzslog2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiupc5alowydj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyagd5chqqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycoczaeqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyegczweqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyehcpclowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygncpskpgsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyohczadpqmdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyond5iepgwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyshajogogidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@sel.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@gator[1].txt -> TrackingCookie.Gator : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-attcorp.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
      • Niles3366

        20 Posts

        595

        0

        Posted September 21st, 2006 03:00

        Here is HJT
         
        Logfile of HijackThis v1.99.1
        Scan saved at 11:17:54 PM, on 9/20/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Windows Defender\MsMpEng.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\CTsvcCDA.exe
        C:\Program Files\Symantec AntiVirus\DefWatch.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\BCMSMMSG.exe
        C:\Program Files\Symantec AntiVirus\Rtvscan.exe
        C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
        C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
        C:\WINDOWS\system32\CTHELPER.EXE
        C:\WINDOWS\System32\DSentry.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\Dell\Media Experience\PCMService.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
        C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\PROGRA~1\SYMANT~1\VPTray.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Dell Support\DSAgnt.exe
        C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
        C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
        C:\WINDOWS\system32\hpoipm07.exe
        C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
        C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Hijackthis\HijackThis.exe
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDsHkhWqtO3evZFfl7nIWD0usKoOG48ThBP49/3Ubc9FaaSxbtidWnb28jA+mN5H42e+DXWxXH3TjwMFFn5Bo7JOESsRkh191tpfoQwqwMXbg+RYouPOU7N3GPpqioiESbx4ndvn2LzJpglaaNxD1ZsPpeyb3VvvsOS13lRY1OszEX6w5SR+HzM2KbR/Zj/mKm19vnq/yuo7E=
        R3 - Default URLSearchHook is missing
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
        O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing)
        O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll (file missing)
        O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing)
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
        O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
        O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
        O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
        O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
        O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
        O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
        O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
        O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
        O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: HPAiODevice(hp psc 900 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\Bin\hpobrt07.exe
        O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
        O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
        O15 - Trusted Zone: *.musicmatch.com
        O15 - Trusted Zone: *.musicmatch.com (HKLM)
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
        O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
        O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
        O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099361013330
        O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http://www.mindavenue.com/Downloads/AXELPlayerAX_Win32.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121049800390
        O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
        O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/ftp.coupons.com/v3123/cpbrkpie.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
        O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.0/installer.exe
        O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
        O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
        O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://neo2.agribank.com/dana-cached/setup/JuniperSetup.cab
        O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
        O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
        O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
        O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Default\Desktop\ewido anti-spyware 4.0\guard.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
         
      • Niles3366

        20 Posts

        737

        0

        Posted September 21st, 2006 03:00

        \Local Settings\Temp\UGPw30K.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UIG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UOH0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UWNhn.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UWQTu.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UcPFOH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UrF.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UtGf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UyPVP.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\UzESw.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\V10zJ2Z.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\V4.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\VHCGPEQc.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\VIqpgrYQm.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Vu5MJ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\VyyVkbYf2.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\W9EkB.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\WFooF.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\WIcHu.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\WSDW.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\WZM9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\WoDr4rHPk.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Wyec9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\X4.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\X7B4EpZY.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XPKQeILc.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XbQ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XdG0lBQ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XeuJLoYw.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XkL.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\XsUd.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Xx3.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Y.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Y4CfQ8.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\YNZ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\YncIk.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Z4.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZD9WH1T.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZDFo9mZ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZLPh00Gx.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZX5Q2Pvv.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZbsJ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Zdg.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZoG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ZvOUAYY.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\a2mEk3Y3u.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\a7Ea.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\aGn.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\aMuqu2.exe -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\aX0nW9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ab3FSE.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\aeH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\aoy.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\b5QRg.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\b5V.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\b8d.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bAPO0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bFcY4p4B.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bRtY9P6ab.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bY.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bi4.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bmv.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\boc2GZzl.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\bx3wfnA.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\byQIwm.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cB.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cDWcm.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cN.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cVEMa5.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cWv.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cecjQG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ctlIVZ5pG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\cvZqHVs.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\dm5LrPt.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\eE.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\eUgmbWz.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\enxjE.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\f.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\f4CAvP.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\f9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fAps.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fJnF0Un.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fKgD.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fVPfwXD.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fZp2rW.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\fnnpZxxs.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\foZ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\gNtP.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\h0BV0IQ.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\h1HvoTejf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\h55N5Xz.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hJCaG3F.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hO7TLj.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hS.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hTrJu.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hY.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\halTSSTzz.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hmW.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hpk.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hqmgiUB.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\hy8YNze0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\i6t.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\i9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\iBthP.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\iJzyAG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\iOMQV3bH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\iSy1jt.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ier0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
      • Niles3366

        20 Posts

        593

        0

        Posted September 21st, 2006 03:00

        C:\Documents and Settings\Default\Cookies\default@ehg-etoys.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-findlaw.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-fredericks.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-hasbro.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-helio.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-idg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-ifilm.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-inforspaceinc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-nestleusainc.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-quepasacorp.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-reunion.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-sonyny.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-space.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-techtarget.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-viacom.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ehg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@phg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ehg-viacom.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ehg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter2.hitslink[2].txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@incredifind[1].txt -> TrackingCookie.Incredifind : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter13.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter3.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@counter13.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@counter15.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@counter3.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@cs.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@vdn.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@vdn.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1097\A0114979.exe -> Trojan.Agent.az : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\SEPInst.exe -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\09E74A44-DCB2-4671-8C5D-FB24FD\2CF0B655-D18F-4A47-8D4C-95C98C -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\0BC42220-DE43-4FC9-9FFF-1AB816\CCAEB9B9-E62D-4061-A373-C237F7 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\0FD0A1BE-6E9A-4729-80DA-DCFE5C\D95E6DB4-D2CA-4EAC-91FA-CD6843 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\80CC79C5-EC23-4383-A152-BF39CE\A49C9B92-8BCB-4AB7-9868-016E86 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\A8F915BD-EA51-4026-9292-CB552B\258F1EE4-6D8A-450B-8AE7-BF6F1B -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\BA48A7A0-4F8C-4958-BB69-90D1FE\C4F659F9-F2CB-483C-9DAA-9D28E6 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\BDCEF6FE-0328-4B30-B190-85DD52\1A94DF96-4A7E-4ADF-8FA9-5FD397 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\D0F7D88E-CA2B-4FD7-A955-B454E6\23234509-8C7A-4ED6-9B0E-087C04 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\D6657A86-150B-422C-8590-35583C\2CFE8217-BBF2-48EB-A293-B5F434 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\DE61324E-F503-481B-B693-D76823\48B5D78D-EBBC-4D6B-B6B6-869458 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\E722E8D4-F44B-49B9-88C4-A90D57\77956782-C2CD-4A98-B198-DDED90 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\F8269665-D485-45E2-814D-392092\5F7E4EB3-CDFB-4815-AB02-BDDE72 -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1003\A0101290.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1008\A0101308.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1012\A0101326.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1019\A0101347.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1024\A0101427.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1028\A0101446.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1030\A0101458.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1036\A0101491.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1038\A0101507.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1039\A0101509.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1043\A0102524.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1056\A0102610.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1058\A0103621.dll -> Trojan.Septic.a : Cleaned with backup (quarantined).
      • Niles3366

        20 Posts

        737

        0

        Posted September 21st, 2006 03:00

        C:\Documents and Settings\Default\Local Settings\Temp\2t9ay.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\2xH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\351Uk.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3PZxUTM.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3RSv.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3W9Jq75.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3k85YIxJm.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3t6yHw.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\3tZgTwW.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\45KTQ2Yip.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\4DrAN.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\4H1.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\53Icg94Iu.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\55.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\56dNUH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5GzNoFn1.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5Z.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5gXLMShU.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5n7Xh6BH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5w.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\5xY8cU0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6B0OVFrRH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6I58J.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6QbqtG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6Qe1A2.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6VoHP2A.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6Z3Bot.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6d.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6l3.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6rd4V5.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6v.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6yuICFf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6za33EP.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\6zdEa0m.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\810cKqAD6.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\822sH.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8BAQA.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8M15h.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8TahN.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8a.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8mim5.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8sCkfS.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\8zMxL6.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\95en.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\98SSRpzb.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9H.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9J8YlJmRf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9R.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9e9.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9i.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9lfK.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9rr2.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9u.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\9wN.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\A0.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\A2Yz2Hy.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\A9R2DQGM6.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\AAqs.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\AKhD.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\AYhBD7tBs.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\AhRiB.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\AkFi73.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Ao.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\ArItzn.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BI.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BTF.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BW.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BY30OZu.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BgQYD.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Bh.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\BoG.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Bq.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\CH2DoXLm.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\CHZ2hA.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\CMbjDXi.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Ca9FbyJN1.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\CajzQOj.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\D6.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\DXM.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\DY.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\DfjgSClUA.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\DjY2Lm4kh.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\DobJD.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Dw9WdVAza.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Dx2U.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\EAf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Ed8xuVNKw.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\F3.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\FFkhvuf.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\FGd0Hv.dll -> Adware.Midadle : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\FGn.dll -> Adware.Midadle : Cleaned with backup (quarantined).
      • Niles3366

        20 Posts

        593

        0

        Posted September 21st, 2006 03:00

        HKLM\SOFTWARE\Classes\Sep.Search\CurVer -> Adware.SEP : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SEP -> Adware.SEP : Cleaned with backup (quarantined).
        C:\Program Files\SEP -> Adware.SideFind : Cleaned with backup (quarantined).
        C:\Program Files\SEP\Uninst.exe -> Adware.SideFind : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\newsreadericon.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\newsreadericon_over.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\recipes.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\recipes_over.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaver.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaverA.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\contexts -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\contexts\Travel.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\contexts\error.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\contexts\related.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\contexts\travel.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\images -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\All Users\Application Data\Starware\images\walertXP.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\PopupBlocker -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Recipes -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Recipes\RecipesOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Recipes\RecipesOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Screensavers -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Screensavers\ScreensaversOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Weather\AlertArchive.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\StarwareConfig.xml -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\StarwareUninstall.exe -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\bin -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\bin\Starware.dll -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\brand.bmp -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\icons -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Program Files\Starware\icons\star_16.ico -> Adware.Starware : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\CLSID\{CA356D79-679B-4b4c-8E49-5AF97014F4C1} -> Adware.Starware : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Classes\CLSID\{D49E9D35-254C-4c6a-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{D49E9D35-254C-4c6a-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Starware -> Adware.Starware : Cleaned with backup (quarantined).
        HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D49E9D35-254C-4C6A-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
        HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D49E9D35-254C-4C6A-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Od5.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\update_1.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1080\A0113842.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\WINDOWS\SYSTEM32\ab3FSE.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\3B3228EA-8D7A-4078-B56E-AAE3A5\8F5F44A6-5F5F-4A35-8484-7A9712 -> Downloader.Apropo.ab : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\4DC98390-2B7F-4650-BD3F-C3A1AD\2BC72515-DDE0-470E-9B9E-AA2820 -> Downloader.Braidupdate.d : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\F21B95EB-D90C-403C-87CC-7951D0\EEB94DA1-D525-4AC3-A356-C2D373 -> Downloader.Braidupdate.d : Cleaned with backup (quarantined).
        C:\incredifind.exe -> Downloader.Keenval : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\790E9A9D-D6E4-43D8-9BC7-222EE0\0040FE0E-953D-4B51-9F35-BA0A6D -> Downloader.Small.asf : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\i13E.tmp -> Downloader.Totavel.a : Cleaned with backup (quarantined).
        C:\Program Files\Microsoft AntiSpyware\Quarantine\D70CD7A9-02B9-44B7-B7B9-4591AC\BA04AB88-03CA-43A1-AFEB-E39553 -> Hijacker.Agent.dh : Cleaned with backup (quarantined).
        C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Temporary Internet Files\Content.IE5\9VVZDPGM\jsmain[2].js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Temporary Internet Files\Content.IE5\V2SFV98T\jsmain[1].js -> Not-A-Virus.Exploit.IframeJS : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@adc.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@rotator.dex.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Cookies\default@thunderbolt.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
        C:\Documents and Settings\Default\Local Settings\Temp\Cookies\default@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined).