Reply

Join Date: Apr 2006
Posts: 5
Reputation: abha is an unknown quantity at this point 
Solved Threads: 0
abha abha is offline Offline
Newbie Poster

Freeprodtb!!

 
0
  #1
Apr 23rd, 2006
This is really irritating me...I went through websites and tried here and there...but I am not sure whether it has worked or not...Here are my HJT files...please help!

Logfile of HijackThis v1.99.1
Scan saved at 1:02:52 AM, on 4/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\windows\mousepad13.exe
C:\Program Files\Network\ipnetwork.exe
C:\Program Files\Spyware Nuker\swnxt.exe
C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Common Files\Windows\services32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\YWJoYQ\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\abha\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard13.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname13.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad13.exe
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [SWN2] C:\Program Files\Spyware Nuker\swnxt.exe /h
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - HKCU\..\Run: [HP Mobile Printing] C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-110-12-0000137.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: svchost.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
O21 - SSODL: ECCEBHCG - {2D3033ED-1E8A-1569-3317-1FDD6211340E} - C:\WINDOWS\System32\Dakgiood.dll (file missing)
O21 - SSODL: mtklef - {3583E7DB-E99B-447B-2C9D-FC0EF467A8A8} - C:\WINDOWS\System32\avzbw32.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\YWJoYQ\command.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 1,605
Reputation: 'Stein is on a distinguished road 
Solved Threads: 104
Team Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Freeprodtb!!

 
0
  #2
Apr 23rd, 2006
Yep, you're sorta infected.

Let's start by uninstalling the following using Add/Remove Programs:

Accoona
Spyware Nuker



Then, download Ewido Security Suite.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click Update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display "Update successful"

    -=-=-=-=-=-=-==-==-=-= End here to download but not scan -=-=-=-=-=-=-==-==-=-=
  • Click on Scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.


After this, download CCleaner.
Then, follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the "My Computer" icon.
3. Select the "Tools" menu and click "Folder Options".
4. After the new window appears select the "View" tab.
5. Place a checkmark in the checkbox labeled "Display the contents of system folders".
6. Under the "Hidden files and folders" section select the radio button labeled "Show hidden files and folders".
7. Remove the checkmark from the checkbox labeled "Hide file extensions for known file types".
8. Remove the checkmark from the checkbox labeled "Hide protected operating system files". 9. Press the "Apply" button and then the "OK" button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


Now, install the program. Open it, and choose the 'Options' tab. Inside, hit the 'Custom' tab, and add the following folders (Note: Not all of these files are on every computer. If one of these isn't present, skip it):

C:\Windows\Temp
C:\Temp
C:\Documents and Settings\<Every user listed>\Local Settings\Temp
C:\Documents and Settings\<Every user listed>\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\<Every user listed>\History
C:\Documents and Settings\<Every user listed>\Cookies
C:\Windows\Prefetch


After doing this, move back to the 'Cleaner' tab, and inside this, be sure your open to the 'Windows' tab. Inside, check the box labeled 'Custom Files and Folders'.

Next, after following all of these steps, you're ready to scan. Run scans in both the 'Cleaner' and 'Issues'. Note: It might take several scans in each to remove all of the junk.



After this, check the following in HJT:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll (file missing)
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard13.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname13.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad13.exe
O4 - HKLM\..\Run: [SWN2] C:\Program Files\Spyware Nuker\swnxt.exe /h
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - Global Startup: svchost.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html



Then, reboot into safe mode and delete the following:

C:\Program Files\DNS
C:\windows\keyboard13.exe
C:\windows\newname13.exe
C:\windows\mousepad13.exe
C:\Program Files\Spyware Nuker


After this, restart your computer and post the Ewido log, and a new HJT log.

Thanks.
Now if ya like the help ya could always raise our reputation...
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5
Reputation: abha is an unknown quantity at this point 
Solved Threads: 0
abha abha is offline Offline
Newbie Poster

Re: Freeprodtb!!

 
0
  #3
Apr 24th, 2006
Thank you so much..Well the toolbar and the popups and everythin is gone!!

..but still I hope there arent anymore infections..so here are the files..

edwido:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 12:47:11 PM, 4/24/2006
+ Report-Checksum: 5D66ED1A

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{364B6276-C6C1-40B6-A6D7-6C48871FD707} -> Adware.Accoona : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6001CDF7-6F45-471b-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-1292428093-1614895754-839522115-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-1292428093-1614895754-839522115-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup
[656] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup
[852] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1236] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1520] C:\WINDOWS\YWJoYQ\command.exe -> Adware.CommAd : Cleaned with backup
[1800] C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
[1804] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1812] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1856] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1868] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1876] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1892] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1848] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1956] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[508] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1016] C:\windows\mousepad13.exe -> Hijacker.VB.mo : Cleaned with backup
[1036] C:\Program Files\Network\ipnetwork.exe -> Adware.Maxifiles : Cleaned with backup
[1092] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[700] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[1420] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[2060] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[2092] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe -> Dropper.VB.lu : Cleaned with backup
[3364] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[4040] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[3276] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
[2488] C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Error during cleaning
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OHAVOHAR\xxxxxxxxx[1] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OHAVOHAR\xxxxxxxxx[2] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OHAVOHAR\xxxxxxxxx[3] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OHAVOHAR\xxxxxxxxx[4] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WTQ7KL6B\xxxxxxxxx[1] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXI34X23\xxxxxxxxx[3] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXI34X23\xxxxxxxxx[4] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXI34X23\xxxxxxxxx[1] -> Worm.Padobot.z : Cleaned with backup
C:\WINDOWS\system32\csrrs.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\system32\rar.exe -> Dropper.VB.mn : Cleaned with backup
C:\WINDOWS\Temp\Cookies\abha@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\abha@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\keyboard12.exe -> Downloader.VB.abd : Cleaned with backup
C:\WINDOWS\mousepad12.exe -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\newname12.exe -> Downloader.VB.aaf : Cleaned with backup
C:\WINDOWS\YWJoYQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\YWJoYQ\command.exe -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\keyboard13.exe -> Downloader.VB.abj : Cleaned with backup
C:\WINDOWS\mousepad13.exe -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\newname13.exe -> Downloader.VB.aaf : Cleaned with backup
C:\WINDOWS\DH.dll_ -> Hijacker.Small.jf : Cleaned with backup
C:\WINDOWS\b.exe -> Backdoor.Rbot : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe -> Dropper.VB.lu : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-5.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-4.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-3.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-7.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.12:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-8.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Zedo : Cleaned with backup
-> : Error during cleaning
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-9.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-10.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-11.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-12.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-13.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-14.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-15.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.11:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-16.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-17.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-18.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-19.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Fastclick : Cleaned with backup
-> : Error during cleaning
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-20.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-21.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-22.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-49.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-50.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.6:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-51.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.7:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.25:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.26:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.27:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.28:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.29:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.30:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.31:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.32:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.33:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.34:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.35:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.36:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.37:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.38:C:\Documents and Settings\abha\Application Data\Mozilla\Firefox\Profiles\ystxomhg.default\cookies-52.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.14:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.17:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.19:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.20:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.37:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.38:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.39:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.40:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.43:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.44:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.45:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.46:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.50:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.51:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.53:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.54:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.55:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.57:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.63:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.64:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.65:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.66:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.67:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.68:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.69:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.72:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.81:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.83:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.84:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.85:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.86:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.90:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.91:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.101:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.104:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.115:C:\Documents and Settings\abha\Application Data\Phoenix\Profiles\default\nhc3fxcf.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\services.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Network\ipnetwork.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0017156.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0018154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0018157.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0018160.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0018165.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0019154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0019157.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0019159.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0019162.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0019167.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023157.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0020154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0020157.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0020158.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0020165.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0021154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0021157.EXE -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0021158.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0021166.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0022154.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0022157.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0022160.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023160.EXE -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023175.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023176.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023177.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023178.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023179.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023180.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023181.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023182.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023183.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023184.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023185.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023186.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023187.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023188.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023189.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023190.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023191.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023192.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023193.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023194.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023195.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023196.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023197.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023198.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023199.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023200.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023201.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023208.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023211.EXE -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023212.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0023219.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024208.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024211.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024214.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024222.dll -> Hijacker.Small.jf : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024226.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024227.exe -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024228.exe -> Downloader.Adload.as : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024229.exe -> Downloader.Adload.as : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024230.exe -> Downloader.VB.abm : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0024232.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0025208.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0025211.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0025217.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026208.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026212.exe -> Hijacker.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026214.exe -> Downloader.Small.buy : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026215.exe -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026217.exe -> Worm.Padobot.z : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026221.exe -> Dropper.Agent.aac : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026224.EXE -> Adware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{33DAAEC9-C8E1-4EC8-9FD9-AB1E6E4538DB}\RP30\A0026225.exe -> Adware.SaveNow : Cleaned with backup
C:\Setup.exe -> Dropper.VB.mn : Cleaned with backup
C:\iexplore.exe -> Dropper.VB.mn : Cleaned with backup
D:\_\xzxzxzxzxzxz.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\xzxzxzxzxzxz.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\iRadio v1.5.0.512.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ice Age The Meltdown Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ubersoldier ISO - Reloaded.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Godfather Rip.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PixelGenius PhotoKit Color 2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Beach of a Woman Screensaver.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Beginning Linux Programming 3rd Edition.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Template Monster Font Pack.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Brushes for Photoshop.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\File Recover v6.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinRAR v3.60.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TinyXp Revision 4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ulead® PhotoImpact® 11.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ice Age 2 The Meltdown (2006).exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Iron Warriors T72 Tank Command (2006) PC.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Godfather (2006) PC [DVD ISO].exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\533soft Icon Changer 1.854.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ImTOO RM Converter 2.1.62.0412b.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Multi-DB Querier 1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ImTOO MP4 Video Converter 2.1.62.0412b.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\UFS Explorer 1.6.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Personal Passworder 3.82.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\EarthView 3.4.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\cFos Speed 2.13 Build 1094 Beta.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Email Questionnaire 4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Apollo DVD Copy 4.6.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Disk Space Inspector 3.40.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic Translator V6.00.5777.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\File Renamer Pro v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AVI DivX to DVD SVCD VCD Converter v1.46.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\iRadio v1.5.0.512 WORKING.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Pokerbot Pro.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Signature Creator.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ashampoo AntiSpyWare v1.20.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Automize 7.0 Beta 6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MagicTweak 3.30.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\123 Video Converter 3.5.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ImTOO Audio Encoder 2.1.55.0411.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Access Boss 2.3 beta 1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinRAR 3.60 Beta 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\All My Movies 3.9 Build 1208.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WebSeeker 6.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Xilisoft Audio Converter 2.1.55.0411.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Xilisoft Video To Audio Converter 2.1.62.0412b.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Allok AVI MPEG WMV RM To MP3 Converter v1.5.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SpyFerret v5.02.710.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Anti Trojan Elite 3.6.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Dr. DivX 2.0.0 beta 9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Hide IP Platinum v2.61.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XP Tools v5.8.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic Utilities 4.23.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PolyView v4.20.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Panorado v3.3.1.76.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ACDSee Pro v8.0.67.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MemoriesOnTV Pro v3.01.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Flash Player Pro v3.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\File Securer v3.93.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Steganos SAFE PROFESSIONAL 2006 v8.0.12.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ultra Video Converter v1.58.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Top 10 IP Utilities All In One -.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WeBuilder 2006 v7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PodXP v1.1b.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy FlashMaker v1.3.415 -.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Internet Explorer 7 Beta 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Photo Rescue Pro 3.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Crystal Player 1.97 Pro.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TopLang Desktop Lock v7.0.12.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Fix-It Utilities 6 Professional.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Amor Video Joiner v2.21.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Norton SystemWorks 2006.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Microsoft Office 2006.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Korean Dictionary v1.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\EZ Soft Audio Recorder Pro v3.13.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Registry Mechanic 5.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Absolute Uninstaller v1.52.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\StyleXP 3.18 -.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Photo Frame Show 1.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Symantec Ghost Solution Suite v1.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Motocross Madness 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Hitman 3 Contracts.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Encyclopedia Britannica 2006.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tweak-XP Pro v4.07.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\File Recover v6.0.0.32.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\N1 DVD Ripper 2.7.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Window Washer 6.0.5.409 - Retail.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Fun Photo v4.2 Full.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ultimate Troubleshooter 2.83.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Vista Customization Pack 3.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Selteco Flash Designer 5.0.23.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\VLMenuPlus v5.0.059 ActiveX.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Nikon Capture v4.4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Apolisoft MCatalogue v2.7.4.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Golden Oldies.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TetrixMania v1.06.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TextPad v4.7.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Auto Media Play Studio.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Night Mission Pinball.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Fast Cleaner 3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Champion Backup v1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CD MP3 Burner v1.72.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advanced CD Ripper Pro v2.32.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ad0be Dimensions 3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Mixed Up MotherGoose.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DameWare NT Utilities v3.72.0.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\IGI 2 - Covert Strike.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Arabian Nights.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Graphics Workshop 2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Get Right 4.5 Final.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Serialz DTG 1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Slave Zero.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ACD Systems ACDSee v7.0.47.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AVLORD MP3 CD Ripper v1.0.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy Music CD Burner v3.0.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\i-Sound WMA MP3 Sound Recorder 6.50 Prof.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MP3 Convert Lord v1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\No1 DVD Ripper SE v1.3.36.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PowerArchiver 2004 v9.10.06.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Sony Vegas Movie Studio v4.0a.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PowerPoint2DVD v1.3.5.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FlashOnTV v1.0.0.13.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinImage v7.0.7000.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVDFab Platinum 2.51.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Aurora DVD Copy v1.1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\IM2 1.4.3 Final.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DiAMAR Backgrounds and Textures 4 iSO.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Active Webcam v5.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AeroTags HTML Password Protector v1.40.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ClipMate v6.5.04.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ChoiceMail One v2.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Book Collection Professional v3.05.07.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cyberia Radio v1.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ComputerTime v1.0.0.10.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Search Engine Composer v4.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Web Page Finder v2.1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FileRecovery For SD Card v1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ColorImpact 2.8.1.378.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AnyDVD 4.1.1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinAmp Pro 5.06.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ACDSee PowerPack 7.0.47.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Internet Download Manager 4.02.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advanced MP3 WMA Recorder v5.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cheetah DVD Burner v1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FolderSizes v3.0.0.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ultra Video Joiner v2.3.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ultra Video Splitter v2.8.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cleaner for Amateur Video v1.5.1195.4052.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Winamp v5.06 Pro.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NextLimit RealFlow 3.0.12.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Piranesi 4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\IncrediMail 1710.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Offline Explorer Enterprise 3.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PINNACLE TitleDeko Pro 1.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Auto Power-On And Shut-Down v1.42.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cheetah CD Burner v3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Hidden Camera v2.8.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinDriver for Windows v6.03.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Sysgate Firewall 5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CopyToDVD v2.2.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NeoPaint v4.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FireGraphic v6.0.607.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SearchIt v2.0.8.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Global Mapper v5.04.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Windows Classic Arcade.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Test Drive 6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Motor City Online.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Americas Army 1.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SuperMario PC Final.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Deadly Dozen.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\System Analazer.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FlashAdmin v1.01.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Alive MP3 WAV Converter v1.5.8.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Atomic Sevens v1.01.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NeroMediaPlayer v1.4.0.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Janitor Joe.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Kings Quest 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Bettergrades Science Quiz v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Bettergrades Higher English Workout v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Bettergrades Higher Mathematics Quiz v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Screenswift v4.1.546.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Morello axsImaging ActiveX v2.0.0.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ace Video Workshop v1.4.41.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ease Audio Converter v2.90.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MemoriesOnTV Pro v3.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Web Password Wizard v2.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MythusCDRipper v3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Aone Movie DVD Maker v1.5.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Podcast Station v1.0.0.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PDF To Word Converter v2.01.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XtraTools 2006 v04.17.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NewsReactor v1.0.9000.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\e-PDF To HTML Converter v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Fairdell HexCmp v2.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Flash Designer v5.0.23.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XPCSpy Pro v2.61.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\VSO PhotoDVD v2.2.1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advexsoft Disk Space Inspector v3.4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Spyware Doctor v3.8.0.1557.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Access Remote PC v4.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Agama Web Buttons v2.61.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AMF Back Me Up v4.0.0.1420.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\7 Sins.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Call of Cthulhu - Dark Corners of the Earth.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Big Night DVDRip.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Mad Max 2 The Road Warrior.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\House Of Flying Daggers DVDRip.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Star Wars Empire At War ISO.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Condemned Criminal Origins ISO.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Steganos Security Suite 2006 v8.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ZoneAlarm With Anti-Spyware v6.1.514.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Total Video Converter v2.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Movie DVD Maker v1.3.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ultra Tag Editor v2.20.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Digital Audio Editor v4.3.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cheetah CD Burner v3.31.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Video-AVI To GIF Converter v2.0.10A9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVD Power Burner Pro v2.7.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Acronis True Image 9.0 Build 2277.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Registry Repair 2006 4.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Alawar PacRush 4.80.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DivX 6.02.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Acronis Disk Director Suite 9.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\BitDefender Plus 9.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WavePad 1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\VueScan Professional v8.3.04.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DrWeb v4.33.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Synapticad AllProducts v10.13a.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Stereogram Magician v3.02.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MaxBulk Mailer v4.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CASE Studio v2.21.0.333.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Research Systems ENVI v4.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Antenna Web Design Studio v2.6.0.120.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AI Picture Explorer 8.1.0.8100.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MP3 Tag Clinic 4.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Media Center 11.1.39 beta.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\HTML-Optimizer 9.4.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Alo CD.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Willing Webcam Lite 3.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Dark Mailer.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\3D MP3 Sound Recorder 3.8.13.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Apollo Audio DVD Creator v1.1.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Bad CD Repair Pro v4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Photo Collage v1.32.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Selteco Flash Designer v5.0.22.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Style XP v3.13.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Offline Explorer Enterprise v3.8 Build.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Hpmbcalc v2.30.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PDF to Word v1.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Xara Xtreme 2.0a DL.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PS FileRenamer v2.46.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Network LookOut Administrator v1.7.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Find it! v1.10.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Slots Scary v4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Slots GoWest v3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SnagIt 7.25.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tray Commander 2.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Aurora MPEG To DVD Burner v4.738.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVDFab 1.99.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ProShow Gold 2.0.1567.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Power Spy V4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Mass Downloader 3.2.0.631.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Webroot Spy Sweeper 4.5.5 Build 604.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVD Encoder v2.06.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Acronis True Image 9.0 Build 2302.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\X-Setup Pro v7.2.360.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Naevius CD.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Photogather Luxury v7.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Shut Down Expert v4.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Spot Auditor v1.9.25.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVD Copy Tools v3.6.1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Hide IP Platinum 2.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Photoshop Inky 2 Brush.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Virtual CD File Server 7.1.01.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FlashFXP 3.3.4 build 1109 Beta.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Winamp Skins Creator 1.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FlashFXP 3.3.4 build 1109.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XoftSpy 4.19.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PC Auto Shutdown 1.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Digital Audio Editor v4.3.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\BadCopy Pro v3.80.1108.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Mobile Ringtone Converter v2.3.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Lavasoft Personal Firewall 1.0.543.5722.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Focus Photoeditor 4.1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CD Bank Cataloguer v2.70 Build 199.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Public PC Desktop v2.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic DVD Ripper v3.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\IncrediMail Build 1836b.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ashampoo Burning Studio 5 5.0.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\BlueMountain Ripper v1.2.3 for MSN.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Fanix As-U-Type v3.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Apollo DivX To DVD Creator v1.20.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\BlindWrite 5.2.23.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advanced Spyware Remover 1.54.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\McAfee Spamkiller v7.0.23.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Making Waves Studio v5.29.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Bat v3.62.14 Pro.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Flash Decompiler 2.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic DVD Ripper 3.61.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Motor city online.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Iso buster.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\U-Wipe v2.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SpamGunner v1.15.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CD MP3Terminator 1.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Selteco Flash Designer.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tetris 4004.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Flash FXP 1.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinMPG Video Convert 1.50.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\3D Flash Animator v3.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\A Screensaver Creator 3.24.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Roll em Up Pinball 1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CD Cover Maker v1.02.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Arkanoid -The Virtual Isles v3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CDR Win 5.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TVTonic 2.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVD Genie 4.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ZoneAlarm Pro 3.1.395.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PocoMail v4.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MightSoft Audio Editor Pro v2.01.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Windows History Sweeper Helper v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FTPRush v1.0.0588.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Digital Audio Editor v6.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CoCsoft StreamDown v5.8.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PDF-Convert PDF Encrypt Tool v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Link700 v1.1.4.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\LabelsWin v1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\TitleBarClock Pro 5.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Smart Undelete v2.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Serial to Ethernet Connector 3.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Movie Writer Pro v2.85.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advanced Host Monitor v5.88.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ad Muncher v4.7.22200 BETA.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Nero SIPPS 2.1.3.61.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Selteco Flash Designer v5.0.23.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Digit Magazine May 2006 [ebook].exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Digital FilmTools 55mm v6.0 for Photoshop.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AtLast SketchUp v5.0.260.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Larry The Cable Guy Health Inspector DVDRip Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Nitro PDF v4.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Xingtone Ringtone Maker v4.2.19.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NOD 32 AiO.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PowerArchiver v9.61.01 Final.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Harry Potter And The Prisoner Of Azkaban Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Satanic Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\2Pac ReSurrection Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Top Gun Xvid.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\King Kong.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Starship Troopers.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Hulk.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Area 51.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Adobe Acrobat 3D 7.0.7.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\MOBILedit 2.0.0.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinXP Manager v4.97.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic DVD Ripper v4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Recover My Files v3.94.4393.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Detonator [2006 ~ DVDRip.XviD].exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Wild [2006 ].exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Privacy Shield 3.0.25.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Atlantis 1.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Road Rush 1.8.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy DVD CD Burner v3.0.65.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy DVD To DVD Copy v3.0.29.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Throttle v6.12.2006.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ocean Diver ver. 1.0 Full.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Infinite sudoku.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Theme Hospital Full.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Toejam & Earl (Mega Drive).exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Shapy v1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tanks Evolution 1.04.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Syberia 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\A Snakes Life v2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FIFA 2006 Utilities.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Backup2005 Synchronizer ver. 3.2.3.27.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Backup2005 Pro v4.3.2.136.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AVID SOFTIMAGE XSI ADVANCED V5.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\EncSpot Pro 2.1 build 494 (Full).exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AutoFX Mystical Lighting.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Wtools32 v1.6.28.198.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PC-Cillin 2004 v11.0 b1253.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\The Bat! v2.02 CE RC2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Terragen 0.9.19.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinPatrol 6.0.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CS Multiplayer Cheats Pak.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Download Accelerator.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\James Bond 007.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Rocchetta Label Maker.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Akala Exe Lock v3.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\International Superstar Soccer 3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Empire of Ants.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tiff-PDF counter 1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ace Buddy v3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\X-Plane Sim.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Backup Magic 1.6.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Gadget Tycoon.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\69 Babes ScreenSaver.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Will Rock.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Rails Across America.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\War of the States.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Skateboard Park Tycoon 2004.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Nero Sepps 20.43.13.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NeroMix v1.4.0.16.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Camtasia Studio 2.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\3D MP3 Sound Recorder 3.6.5.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Motion Studio v.3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Crash Proof Retail.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PartyDJ v5.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cheetah DVD Burner v1.14.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Street Sports BasketBall.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PC Pool Challenge.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Freedom Figthers ISO.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Add Remove Plus 2003 v4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\3D Mark 2003.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CDRWin 5.05.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FairStars Recorder 2.44.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Daily Inventory v4.7.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\GoldenHawk CDRWin v3.9F.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Poppers v1.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Napster 2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Macromedia Fireworks MX 2004.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Lavavo Audio CD Ripper 2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Advanced Color Tool v1.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Protector Plus 2000 v7.2.E05.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Blaze DVD Player 2.0A.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Eudora 6.0.22 Email Pro.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\1 Cool Button Tool Flash 5.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Qualcomm Eudora v6.0.2.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\STARR PC.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ad Popup Killer 4.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CoordTrans v1.0.14.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVDX Platinum 2.10.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\321 Studios 6 in 1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Styler 1.38.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Selteco Photo Lab v2.2.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Love Actually.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Transporter 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Red Eye.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\House Of Wax.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Gangs Of New York.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\xXx State Of The Union.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Harry Potter And The Goblet Of Fire.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Tango And Cash.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Point Tweaker v2.0 for Adobe Illustrator CS2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\COMET Digital Cmuscle System v1.2 For MAYA.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\CoffeeCup StyleSheet Maker v5.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Cinefex 92 Movie Effects Magazine.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Complete Anonymous Web Surfing v3.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\OnyxTREE PALM v6.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Relentless Rapidshare Spyder v5.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Norton Internet Security 2006.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Shade v8.5.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Rapidshare Leecher v4.4.87.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Alcohol 120 v1.9.5 Build 3823.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ulead DVD MovieFactory 5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\GraphicsGale v1.80.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SideFX Houdini Master v8.0.474.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Microsoft Money 2006 Deluxe.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Talisman Desktop v2.98.2980 + Extras.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy DVD CD Burner v3.0.72.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FotoStation Pro v5.2.77.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Privacy Shield v3.0.25.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinRAR v3.60 Beta 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Nitro PDF Professional v4.9.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\My Screen Recorder Pro v2.32.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Site Translator v2.43.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Video Edit Magic v4.15.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Adobe After Effects v7.0 Professional WinXP.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy DVD to DivX VCD SVCD Converter v.3.0.47.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic Music Editor 3.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Recover My Files 3.90.3328.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Traktor DJ Studio v3.0.1.108 (H2O).exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Vista ServicePack 1.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Acronis MigrateEasy 6.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Startup Faster 2004 2.1.2.110.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XP Smoker 4.4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ace Video Workshop 1.4.30.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Outpost Firewall Pro 2.5.370.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Mass Downloader 3.0.567.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\History Cleaner 3.5.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\VueScan Professional Edition 8.1.6.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Translator Internet 1.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SpyBuddy 3.2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Raxco PerfectDisk 7.0.31.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\pdfFactory Pro Enterprise 2.29.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FinePrint Enterprise 5.29.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AceFTP Pro 3.61.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Opera 7.60 Preview 2.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\NeroMix 1.4.0.25.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\VideoCharge 2.3.2.22.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\AcdSee 7.0.43 PowerPack.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\SecurStar DriveCrypt Plus Pack 3.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Download Armor2net Personal Firewall 3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\XP Smoker 4.3.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ZoneAlarm Security Suite 5.5.062.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Virtual CD 6.0.0.6 Network Edition.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Armor2net Personal Firewall 3.13.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Magic Vines 1.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Focus Photoeditor 4.0.5 F.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Adobe Graphics Server 2.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\PC Cillin Internet Security 2005 12.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVD Region-CSS Free 5.58.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\DVDIdle Pro 5.58.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\System Mechanic Pro 5.0c.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FairStars Recorder 2.60.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Add Remove Plus! 2004 5.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Acoustica MP3 CD Burner 4.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Style XP 2.16.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Ashampoo UnInstaller Platinum Suite 1.0.0.0.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\ALZip 5.51.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Flashget 1.65.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\FlashFXP v3.0.2.1045 Final.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Easy HTML Autorun Builder 1.2.0.038.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Trojan Guarder Gold Version 6.41.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\WinTools.net Pro 5.0.1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Trillian 3 Pro Alpha 1.exe -> Dropper.VB.lu : Cleaned with backup
E:\My Music\_\Instant Movie Maker 1.0B05.26C00.exe -> Dropper.VB.lu : Cleaned with backup



HJT

Logfile of HijackThis v1.99.1
Scan saved at 1:30:14 PM, on 4/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Documents and Settings\abha\Desktop\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKCU\..\Run: [HP Mobile Printing] C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
O21 - SSODL: ECCEBHCG - {2D3033ED-1E8A-1569-3317-1FDD6211340E} - C:\WINDOWS\System32\Dakgiood.dll (file missing)
O21 - SSODL: mtklef - {3583E7DB-E99B-447B-2C9D-FC0EF467A8A8} - C:\WINDOWS\System32\avzbw32.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\YWJoYQ\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 1,605
Reputation: 'Stein is on a distinguished road 
Solved Threads: 104
Team Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Freeprodtb!!

 
0
  #4
Apr 24th, 2006
Jeez dude, ya were LOADED .

Ok, not all of it is gone yet tho, so let's do this.

Copy this advise to a Notepad file. Save it to your desktop. We will use it later.

1) Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

2) Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.

3) Once in Safe Mode, please run Killbox.

4) Select "delete on reboot" and put a check in the "unregister dll�.

5) Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\YWJoYQ\asappsrv.dl

6) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

7) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

Let the system reboot.

After this, run SpySweeper again, and repost a log here.

We'll work from there then.

Thanks.
Now if ya like the help ya could always raise our reputation...
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5
Reputation: abha is an unknown quantity at this point 
Solved Threads: 0
abha abha is offline Offline
Newbie Poster

Re: Freeprodtb!!

 
0
  #5
Apr 25th, 2006
I duno what I have deleted in this middle of all this...but then on MSN Messenger...whenever I log back on after shut down....my display pic doesnt stay like earlier..it comes a default soccer ball...I know its a small thing but have I deleted some Messenger Cookie or something

Also there is this movie file in my E: which I guess turned out to be corrupt..its called Crash.avi...its like 700MB and it is not gettin deleted....it says its being used by another user and I think it is really makin my computer slow...Somethin is makin it reallllll slow lately...

Anyway here is the log:
********
11:25 AM: | Start of Session, Tuesday, April 25, 2006 |
11:25 AM: Spy Sweeper started
11:25 AM: Sweep initiated using definitions version 556
11:25 AM: Starting Memory Sweep
11:31 AM: Memory Sweep Complete, Elapsed Time: 00:05:13
11:31 AM: Starting Registry Sweep
11:32 AM: Found Adware: whenu savenow
11:32 AM: HKLM\software\microsoft\windows\currentversion\run\ || vvsn (ID = 140442)
11:32 AM: HKCR\wusn.1\ (1 subtraces) (ID = 140463)
11:32 AM: HKCR\wusn.1\ (1 subtraces) (ID = 635412)
11:32 AM: HKLM\software\classes\wusn.1\ (1 subtraces) (ID = 635554)
11:32 AM: Found Adware: maxifiles
11:32 AM: HKCR\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829231)
11:32 AM: HKCR\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829237)
11:32 AM: HKCR\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829253)
11:32 AM: HKLM\software\classes\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829282)
11:32 AM: HKLM\software\classes\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829292)
11:32 AM: HKLM\software\classes\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829298)
11:32 AM: Found Trojan Horse: berbew trojan
11:32 AM: HKLM\software\microsoft\windows\currentversion\shellserviceobjectdelayload\ || mtklef (ID = 837545)
11:32 AM: Found Adware: findthewebsiteyouneed hijacker
11:32 AM: HKU\S-1-5-21-1292428093-1614895754-839522115-1003\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555437)
11:32 AM: Registry Sweep Complete, Elapsed Time:00:01:35
11:32 AM: Starting Cookie Sweep
11:32 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:32 AM: Starting File Sweep
11:32 AM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
11:32 AM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
11:35 AM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf9159fd2-4912-4901-8754-7929c2193664.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa47e8ecb-a09c-45a7-9b76-42c5e9c48dd7.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsaf0eb201-eff4-4b47-abee-50fa967ad917.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0ec7657c-09be-4855-9324-2a73cfbaba68.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs49a693ab-1e37-423b-b4ed-10b4d4c0409d.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf64924d1-c4ee-4068-9148-7f544e3d8803.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4037243-8a25-4de5-93f3-47db1b63ca1a.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8372053a-af37-46d8-bc5d-7fc92295baf5.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs840eb65d-4454-46e1-bec1-87414d3f4e8e.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8ce92b0e-da97-4ab0-9e83-bc069cc63749.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf868a196-d896-4541-9912-236e181c3821.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa1f339ce-574e-4aef-b30a-3535683941cb.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8fe07122-f586-45b5-bd08-5d09b03a2d09.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6a332bfb-d1a6-4b95-9714-8beeebcd07d6.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf292e121-bcd7-43f4-8bdf-f237fb098cad.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf5e7d549-0553-48f4-9418-569f54793101.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc05b3613-8839-4f30-9129-64c398b0dcf6.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0555680f-b836-49e1-97ec-f46a3d707c3a.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs229ff58d-5b9a-41f1-aaf6-362a351ef7fe.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs72c7ba5e-bfe6-491d-b49f-b9a7d923108a.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs62808b83-e993-4e64-8f83-8681fce8ef01.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa7ab4957-2ab5-45f2-ae34-6b9cb9fd03d2.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa7a54bcf-2877-464b-a5e5-b40ce9246189.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1eecea98-b829-4e2f-84a2-320f9d0a0ad1.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6a223961-7797-4ae3-a908-5b258e58c832.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs80551311-ef5c-4d59-b760-fb685f781b80.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs52e34332-86af-44a5-8350-936232d19af1.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs70571163-e98c-4d44-b977-90ae78df3f6b.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse8c8f8d3-f3a1-43e9-b441-5b33f58ddc82.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs87d70ff4-3ef5-420a-93a7-64256f81779f.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8ed7f65e-bbd3-4ee5-8e80-46923717a8bb.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfd17c1b9-b2da-4ffd-8215-9c3221f84e42.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs63281b89-ee30-4996-9252-9e5916fab086.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8d54c552-f51e-49d3-b168-de122f3919f0.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5f00f762-ea22-42c7-9927-0c5dbe2a5cda.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb795a955-5bb9-458a-8154-06e0cb052da2.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs945abf40-dd13-40b4-949e-1a7cd701c99c.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdd76975a-e5de-4d21-9286-6c52d6f7e016.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0b9730be-b6b7-402f-bf08-48112bcfa516.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0c512cb4-a422-4f95-b03b-8fd9176d1d24.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd3187b0d-9ee9-4971-a881-2dfe676d9623.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfda71552-8a38-4cf4-8b55-15b49e34d0b1.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs745a024c-b4a6-4854-9268-bc64382f2ab5.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs039fd38c-ffa5-4493-8003-b03e2b779499.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsea7d00ec-4567-4775-a5c5-80ed84c08ea3.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2771a487-2536-4c45-a289-972d4181472a.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbe7aa813-e317-46df-9c6e-51ec99ae02a8.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs81e99514-6fc0-412f-a936-5f9a1c3b3874.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8f0053f9-161f-4927-922a-c0f292df5fc4.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs09b001cd-654a-42bb-8382-60295130462e.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs89ae43b2-4ba6-4f95-8857-5ac575dc0e41.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs962355b3-4184-4fba-a0ed-05c2f98df845.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc052a0a3-afe3-4199-ab15-0cd8926cb32d.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf4f71941-ad49-4ab0-ab69-259dfbdf5abd.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs234c43e9-9cd2-473a-bdb4-965f9b07b8df.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscdb07809-74d4-4f0d-a213-f091a3c21161.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs01254a88-58d4-460c-9365-f111b0a3ab46.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2493b08f-a579-40f2-85c3-7eedbb7c74d7.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd7254576-aba4-49f3-891d-71fea7a1b3a5.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs067d9897-6a53-4514-b4c1-ef9821eea296.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscba5aec1-2560-4fae-b6a8-0ecb9bb3cd12.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs26a9e470-e643-4e34-ba15-60401f4a2545.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs330626f4-8412-40a6-8edd-2d1d8b866fe7.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7bba64a4-cd07-45c4-93f4-5354e33dde97.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs906c1163-d41e-4bb8-a593-3b83fb69bc90.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc7f374b6-06c4-4d9a-b1c1-8867c9eda1c7.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd2d0df96-908e-4b39-8060-f7986ae5be75.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4c62ffec-5806-43b8-a57e-3032b6c3773e.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscseb06a895-ca40-40ec-afdc-32a8e8a183f5.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse6c29795-a019-4cb8-8eb1-225dfc556037.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscb675ccb-d9a1-4f06-b1c3-01daa71da596.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf924b9e5-cfeb-4d23-b0a6-22b8aa5e17e6.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f30025a-f84b-4e8a-99b2-d66e42968aa2.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs77c082d9-87be-4eee-8ca8-43a0f82fe993.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs813f1dcf-a1dc-4f45-885e-019200f45756.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs877caca6-8c02-4a8a-ae2c-cc11b7896e25.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3b72a41a-b0b1-4aa5-8e5f-f2badad9bde8.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3aa99b41-1142-48f8-8369-f6c6346d6263.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf5faf38f-1bfe-4e04-9c31-3403a7ee00b6.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6b3f5de4-849e-49fe-925d-1cbcb96365e1.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs36ae5a45-131d-45ce-801e-0293aad770d2.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse21918a4-b9bd-4943-bcbf-7f2efc4ee0cf.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsed5cb1d3-f393-4f24-bb16-cf1fd9adf11f.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd7f32a3f-d110-415a-ad90-383cdd9fb3c7.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21c4b32d-e0f1-4a21-95c3-f3b589fd096f.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs392c713b-cb75-49a4-b88c-7a4d453053af.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf1084593-e5e6-4ac5-ba50-a1541fafd227.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsedaffe07-b2a6-4ec5-8597-8c7dee96e3b4.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb20afb14-9d3b-4a82-ba08-1f781976beb4.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee097584-3579-4001-bd8b-aeb7162cb1ac.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs482b962a-50b1-45b6-999e-a240bdf03afd.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6466cc44-43da-4d5f-aeb8-d4ccf8646ec2.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd5815bbe-054d-43f5-bb24-2878f9f3a7ee.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbe28538e-ebff-434d-9ac5-23592b998e2d.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4dae4c72-3bf8-4015-9f5b-70cdf0a1590d.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1465fa15-112e-4cdb-9576-dd12c9f9206b.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd6683ca2-5bcc-4ecd-81e2-2eddb1636779.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1d25a255-b4c0-4f9d-be5b-a97ccaa2d496.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9ff9af0f-8010-44ef-b138-7089ccef2fbf.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs870a25ef-b700-41cd-b8fe-6260bfec2269.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs425f7210-13e1-4607-93f5-cef3a2245c32.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs320d8acc-ad9f-4646-bdfd-724775a03e61.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs724667bc-b379-49d8-a7fc-46e2c6649950.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs28eb374c-6218-479a-988c-34d1768df35d.tmp". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat.log". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
11:39 AM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
11:40 AM: Warning: Failed to open file "c:\documents and settings\abha\application data\mozilla\firefox\profiles\ystxomhg.default\parent.lock". The process cannot access the file because it is being used by another process
11:42 AM: vvsninst.exe (ID = 74460)
11:52 AM: c:\program files\vvsn (3 subtraces) (ID = -2147480376)
11:56 AM: File Sweep Complete, Elapsed Time: 00:23:09
11:56 AM: Full Sweep has completed. Elapsed time 00:30:14
11:56 AM: Traces Found: 54
11:57 AM: Removal process initiated
11:57 AM: Quarantining All Traces: berbew trojan
11:57 AM: Quarantining All Traces: findthewebsiteyouneed hijacker
11:57 AM: Quarantining All Traces: maxifiles
11:57 AM: Removal process completed. Elapsed time 00:00:13
11:57 AM: Download has been canceled at your request.
********
11:24 AM: | Start of Session, Tuesday, April 25, 2006 |
11:24 AM: Spy Sweeper started
11:25 AM: Download has been canceled at your request.
11:25 AM: | End of Session, Tuesday, April 25, 2006 |

Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 1,542
Reputation: tayspen is on a distinguished road 
Solved Threads: 98
Team Colleague
tayspen's Avatar
tayspen tayspen is offline Offline
<Insert title here>

Re: Freeprodtb!!

 
0
  #6
Apr 25th, 2006
Please attach another HJT log. Thanks.
Firefox
Ewido
Tune up windows
Get detailed system information
My Fixes

Member - Alliance of Security Analysis Professionals - Since 2006
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 1,605
Reputation: 'Stein is on a distinguished road 
Solved Threads: 104
Team Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Freeprodtb!!

 
0
  #7
Apr 25th, 2006
Arg, post a new HJT log (as said Tayspern), and then try running SpySweeper in safe mode. I'm not liking how it didnt scan too well.

Thanks.
Now if ya like the help ya could always raise our reputation...
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5
Reputation: abha is an unknown quantity at this point 
Solved Threads: 0
abha abha is offline Offline
Newbie Poster

Re: Freeprodtb!!

 
0
  #8
Apr 26th, 2006
My MSN problem is sloved and I managed to delete that file..but anyway...

I guess the scan didnt work too well in Safe Mode too...

********
3:35 PM: | Start of Session, Wednesday, April 26, 2006 |
3:35 PM: Spy Sweeper started
3:35 PM: Sweep initiated using definitions version 665
3:35 PM: Starting Memory Sweep
3:36 PM: Memory Sweep Complete, Elapsed Time: 00:01:24
3:36 PM: Starting Registry Sweep
3:37 PM: Found Adware: whenu savenow
3:37 PM: HKLM\software\microsoft\windows\currentversion\run\ || vvsn (ID = 140442)
3:37 PM: Registry Sweep Complete, Elapsed Time:00:00:09
3:37 PM: Starting Cookie Sweep
3:37 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:37 PM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
3:37 PM: Starting File Sweep
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs47fc1583-a740-4daa-99eb-f0863cd7a5ae.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs918996a2-3a77-48e1-9d38-6bb1a2820338.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs0f185535-9d80-4ac3-9d0b-d13a15d0a3f3.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs2ab26d04-9d68-46b5-805e-188d48c2e5a7.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs1ffa15e6-72de-4c56-92cb-12486486e40c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs863d3316-5181-42c3-b2c1-f4aea06b1e0a.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs6de2863e-2fe4-45d1-bb20-aae1348f7f6a.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsae4cb6f5-a0a7-41d2-b801-3d8fe186c8dd.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse11558f8-ad60-4b4d-9d1d-5e0638965ea0.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs475680f6-39ee-4eec-997d-d672a20f7585.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscscc28cd24-f151-4215-8739-5d5a1c818e1c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs4981d0a4-874e-484e-8e61-f274df19bc24.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs38ec2c97-aa3c-49cf-ad4f-8352e91e9c68.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsf11ad080-f78c-415e-b39e-0780086a6f4a.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs558b9aad-6a51-43d0-8cb0-bb10d94b5c8c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs02731f32-1914-4a11-b984-3da6b35dd964.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsaa9b74a3-5f2e-472d-8755-b06fddcbb115.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs1ca6ec0a-0d76-4c23-a463-1b14945903db.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs9a33a8fc-fd09-43f2-b448-e51e961ad83c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs5a65b400-71c2-44d0-af12-26117915c497.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsf56de701-db9e-4a10-8a5a-65ebbdc83e9e.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs02201196-fd4d-47fa-8e0b-e567b20a26e0.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs5271e573-56e8-4f93-b7f9-e998da9c3dea.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsd0ce2b9d-4361-4858-a6f1-98d06b3514ff.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsbf4502c6-e973-4eb4-b5fa-5dde47f60452.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse124d3b1-f875-453f-8860-3521fd696d07.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsbf5a5851-12b3-44e2-8bdd-796faad72265.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs7b6c0f7a-4a6e-49b7-a15c-8e8b79dba6d9.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse60f03d9-9cd1-4648-a631-f75a53896811.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsd2b822e3-0db9-4b59-9679-acf7a2d0f0a5.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs10ae5b75-7200-4182-ad47-8bbc52d81fcc.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs9b361af2-6bcb-495b-a2bd-6eb284493faf.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs32a035c4-595d-4395-85c7-884bf52917d7.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsdea18cdf-eb10-4a59-ba14-5ff907248adb.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsb4e7c878-173d-4246-b3f7-4eee0795957a.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs42b08102-cdc3-4f16-9397-8483d52022b0.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs7de47163-2e6d-4fa5-9884-7b33a02ff073.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs708f6894-3b2e-44fa-b8da-b9bd1f4b7855.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs77634a4e-7b4b-473d-95d4-daac9bf0e3d1.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs9b77ac44-0719-407d-b4a6-17c282626463.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsabd46ec4-f776-47ba-8c66-9836b365401f.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs6a9f4844-5d68-4a7c-bdbc-2160b30f3942.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs36c97cb6-5be0-42e3-aa22-27bda8591b64.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs90fc8dbd-501f-4a91-a5b6-51e51b5dd161.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs221231a5-e5ee-420d-9814-2773685ee6ca.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs88017735-772e-4f62-ae2d-3aebc758dd8d.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs0e19ef32-bb30-47e4-a3bd-38d600ef5005.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs614b1828-94bb-4ff3-8c61-1f10f676efbf.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs8abf43e1-5460-4689-8a26-0e86a77222ab.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsad0a1b13-ca31-4fcd-bde4-7c4f054411aa.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs74561308-12a8-454f-9c6b-d03518f652af.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs12eb414c-b10b-4ff9-8c35-f386951e7af8.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs7bd92745-91eb-460d-bc02-5f9198e6fdfb.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs4cfd6139-c4df-4520-a228-cdd2ad20f22f.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs751911b9-0b72-4826-90c9-3107ce037c36.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs5ff7c7a2-79bd-4338-98e4-943c59bcaa4c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs87b8814c-3c58-4c6f-8cc9-089276b89303.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse83cdaed-3f62-45fb-89b6-d0054c3f126c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs15f1087e-6a36-4226-9ff8-a92d67ff54a4.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs525b136a-2c61-49d8-82aa-fa78122c7f76.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs53850a43-e92f-4663-8bae-e4b33ea7f0f5.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs9dad1842-0a06-4c12-99f3-4b8633facec7.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsf7605656-a2b0-43e7-9473-a663acc36688.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse44521a6-5f91-43e3-a7ea-bc5f289e957d.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs3181e18d-54c3-41d3-a8f7-a7ecdb74b769.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs61f01f4c-3a65-4052-8772-269ea9092dbc.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse13d6c6a-28b7-4bbf-bba2-fd9cdb37d81c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs3ecd41ad-d0cd-43f0-ba9d-1259ffbf59a5.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs5d57139f-6605-4f94-91fe-c415e28a794b.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs313417d2-2190-4cc6-85aa-20922d106004.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs744ecce4-126b-44f4-9256-8c0b4b1bffcb.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs65663e40-9c89-4b45-b282-9f7e9738e270.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs76df751a-db81-4122-92d8-99af8c4c3b42.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs59b9e2bd-4fc2-4b3c-bd55-4c2124974f18.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs4d8d8d41-0f05-4ad0-9ae9-cfc58cddbae9.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsea24a264-5982-4e3f-9ff1-c8105ccc0bc3.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs2e57c573-812c-4157-a3f8-7716bb90bc7b.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs17262ec8-f354-4f2d-9245-727de46fe8c1.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs13ebc996-6c86-4663-91f3-cd522dc53e88.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs9b13fc6e-1e9e-4d15-8479-523dd396b2e2.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse885c624-4b9c-4d35-a61c-1ab39ceee868.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs196c3184-057f-41ea-a6ab-a13bd154e695.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs5085fbf6-6ef6-4724-a1bf-722f26499614.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs6d200297-6597-41bb-87d0-3d39204789bd.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscscb982155-a5cd-4b1e-bd33-466f46d9eb29.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse19011b3-13c7-4ca5-b610-162dbba94234.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs1481fb8c-ce1f-41c4-89c4-c130e833c7cc.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs3dcb37ff-a7ed-4ba5-96db-8ad6513e1a8d.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs907a63b7-85d2-4876-b454-b765edc9c2e7.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs51b66318-d6a6-431c-9f2c-374f2f752093.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsbc826406-38cb-4d67-9aaf-1cbe7db0fb9c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs84b9b637-62f7-4cf7-9877-3b9f291ecf70.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsa696cf4f-889f-42f2-8a60-a6422becc93c.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs7c7e4dd1-c423-4c72-a787-fe22878d255d.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsee876092-e4fa-4c53-b895-f37dc6f4c1fb.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs4bb7d432-d632-4272-8c6b-a83ec404981f.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsa10fbccf-a026-4568-bcb7-2c2b58779e12.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs1fc66a18-9bb9-4100-b2da-c218e15abeb1.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs6cfc6aa8-d1fc-46b0-ac37-5db9e29c67e3.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs10708234-2c7f-49b2-8a4c-889e705344e0.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs2b7ac909-545b-4685-a370-1aba76107a71.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscse7844e19-6a3f-4525-a5cb-13a1c6cc44b2.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscsb6e09d55-6ad2-4cac-b9e4-aeb3676cb07e.tmp". The process cannot access the file because it is being used by another process
3:39 PM: Warning: Failed to open file "c:\windows\system32\config\systemprofile\application data\webroot\spy sweeper\temp\sscs659137ce-86e6-411f-a99d-f8588f1b6a98.tmp". The process cannot access the file because it is being used by another process
3:41 PM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat". The process cannot access the file because it is being used by another process
3:41 PM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:42 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:42 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:42 PM: vvsninst.exe (ID = 74460)
3:45 PM: c:\program files\vvsn (3 subtraces) (ID = -2147480376)
3:45 PM: vvsn.exe (ID = 188685)
3:45 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || VVSN (ID = 0)
3:49 PM: File Sweep Complete, Elapsed Time: 00:12:36
3:49 PM: Full Sweep has completed. Elapsed time 00:14:23
3:49 PM: Traces Found: 8
********
2:50 PM: | Start of Session, Wednesday, April 26, 2006 |
2:50 PM: Spy Sweeper started
2:50 PM: Sweep initiated using definitions version 665
2:50 PM: Starting Memory Sweep
2:54 PM: Found Adware: whenu savenow
2:54 PM: Detected running threat: C:\Program Files\VVSN\VVSN.exe (ID = 188685)
2:54 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || VVSN (ID = 0)
3:05 PM: Memory Sweep Complete, Elapsed Time: 00:15:15
3:05 PM: Starting Registry Sweep
3:06 PM: HKLM\software\microsoft\windows\currentversion\run\ || vvsn (ID = 140442)
3:06 PM: Found Adware: accoona toolbar
3:06 PM: HKCR\abar.abarband\ (5 subtraces) (ID = 520479)
3:06 PM: HKCR\asearchassist.adefaultsearch\ (5 subtraces) (ID = 520489)
3:06 PM: HKCR\typelib\{21f022c8-c045-4555-8a90-651e6a3dc6c6}\ (9 subtraces) (ID = 520528)
3:06 PM: HKCR\typelib\{ea3956d2-ec38-41ab-b601-47aa281e4952}\ (9 subtraces) (ID = 520538)
3:06 PM: HKLM\software\accoona\ (124 subtraces) (ID = 520615)
3:06 PM: HKLM\software\classes\abar.abarband\ (5 subtraces) (ID = 520739)
3:06 PM: HKLM\software\classes\asearchassist.adefaultsearch\ (5 subtraces) (ID = 520749)
3:06 PM: HKLM\software\classes\asearchassist.adefaultsearch.1\ (3 subtraces) (ID = 520755)
3:07 PM: Found Adware: command
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ (7 subtraces) (ID = 892523)
3:07 PM: Found Adware: dollarrevenue
3:07 PM: HKLM\software\policies\ || {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} (ID = 916803)
3:07 PM: HKCR\abar.abarband.1\ (3 subtraces) (ID = 954980)
3:07 PM: HKCR\asearchassist.adefaultsearch.1\ (3 subtraces) (ID = 954985)
3:07 PM: HKCR\clsid\{f80c1d93-0d22-436e-963e-9d3156997a4e}\ (5 subtraces) (ID = 954998)
3:07 PM: HKLM\software\classes\clsid\{f80c1d93-0d22-436e-963e-9d3156997a4e}\ (5 subtraces) (ID = 955055)
3:07 PM: HKLM\software\classes\typelib\{21f022c8-c045-4555-8a90-651e6a3dc6c6}\ (9 subtraces) (ID = 955497)
3:07 PM: HKLM\software\classes\typelib\{ea3956d2-ec38-41ab-b601-47aa281e4952}\ (9 subtraces) (ID = 955503)
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || nomodify (ID = 958653)
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || noremove (ID = 958654)
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || norepair (ID = 958655)
3:07 PM: HKLM\system\currentcontrolset\services\cmdservice\ (12 subtraces) (ID = 958670)
3:07 PM: HKLM\software\policies\ || {6bf52a52-394a-11d3-b153-00c04f79faa6} (ID = 967836)
3:07 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (6 subtraces) (ID = 1016064)
3:07 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (8 subtraces) (ID = 1016072)
3:07 PM: HKLM\software\policies\ || {645ff040-5081-101b-9f08-00aa002f954e} (ID = 1036890)
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{a394e835-c8d6-4b4b-884b-d2709059f3be}\ (7 subtraces) (ID = 1110756)
3:07 PM: HKLM\software\microsoft\drsmartload2\ (1 subtraces) (ID = 1134137)
3:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || uninstallstring (ID = 1134952)
3:07 PM: Found Adware: maxifiles
3:07 PM: HKCR\xbtb04715.ietoolbar.1\ (3 subtraces) (ID = 1156344)
3:07 PM: HKCR\xbtb04715.ietoolbar\ (5 subtraces) (ID = 1156348)
3:07 PM: HKCR\toolband.xbtb04715.1\ (3 subtraces) (ID = 1156354)
3:07 PM: HKCR\toolband.xbtb04715\ (5 subtraces) (ID = 1156358)
3:07 PM: HKCR\xbtb04715.xbtb04715.1\ (3 subtraces) (ID = 1156364)
3:07 PM: HKCR\xbtb04715.xbtb04715\ (5 subtraces) (ID = 1156368)
3:07 PM: HKCR\typelib\{75e46ee7-404b-48ec-9326-c654f21f65bf}\ (9 subtraces) (ID = 1156391)
3:07 PM: HKLM\software\classes\toolband.xbtb04715\ (5 subtraces) (ID = 1156475)
3:07 PM: HKLM\software\classes\xbtb04715.xbtb04715.1\ (3 subtraces) (ID = 1156481)
3:07 PM: HKLM\software\classes\xbtb04715.xbtb04715\ (5 subtraces) (ID = 1156485)
3:07 PM: HKLM\software\classes\typelib\{75e46ee7-404b-48ec-9326-c654f21f65bf}\ (9 subtraces) (ID = 1156508)
3:07 PM: HKLM\software\classes\xbtb04715.ietoolbar.1\ (3 subtraces) (ID = 1156524)
3:07 PM: HKLM\software\classes\xbtb04715.ietoolbar\ (5 subtraces) (ID = 1156528)
3:07 PM: HKLM\software\classes\toolband.xbtb04715.1\ (3 subtraces) (ID = 1156534)
3:07 PM: HKU\S-1-5-21-1292428093-1614895754-839522115-1003\software\director\ || baseurl (ID = 980277)
3:07 PM: Found Adware: zquest
3:07 PM: HKU\S-1-5-21-1292428093-1614895754-839522115-1003\software\microsoft\internet explorer\desktop\components\0\ || source (ID = 1140816)
3:07 PM: HKU\S-1-5-21-1292428093-1614895754-839522115-1003\software\xbtb04715\ (71 subtraces) (ID = 1156401)
3:07 PM: Registry Sweep Complete, Elapsed Time:00:01:22
3:07 PM: Starting Cookie Sweep
3:07 PM: Found Spy Cookie: webtrendslive cookie
3:07 PM: abha@statse.webtrendslive[1].txt (ID = 3667)
3:07 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
3:07 PM: Starting File Sweep
3:07 PM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
3:07 PM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
3:07 PM: uninstall_nmon.vbs (ID = 231442)
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
3:10 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb2994688-84e0-41c6-ba7b-3c0362cbc614.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0fd7eaef-1814-4a83-a103-30a96d0cc4a2.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs48929315-3d33-440a-8e1e-e4db2ff5591f.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc99d1ee7-7708-4373-be06-aee2708b92a1.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6311cb23-eaea-4858-8230-ecab8ff422b8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3a3d492b-b029-4424-9b53-d09058eb7a9e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd633a9b7-2131-4099-9c48-e9d3cb755399.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs17e5eb1a-dd5a-4b3c-9f8f-3d8d1105f732.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs29e75abe-0f36-4267-ad40-a17a55c7f97e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs68cdd601-12bc-41cf-9b92-ff9700befb2b.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6cc6e9f4-b5f1-4cb1-8215-79a7da91ca8a.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3f14c720-ea4a-4b44-b222-c3f5079712f8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs07d8a1d6-b091-4e3f-a7db-7555628191d9.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4b9342fb-9ac4-492b-92fc-bc1e1f7ad4f5.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3ad2fb92-e700-414e-9f75-937b5fd23cf1.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2d005330-87af-45df-94a1-bf956d8774f5.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1637183f-9436-43ef-a73b-a064739432ea.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs80f11280-8b89-46ee-bc76-5af6bd0ae631.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs120acdf1-90f2-44da-bcef-d08dd30d057d.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5f819e90-fdeb-43b2-866b-c07eed6115c8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdbe0b9c4-9b0c-4d9a-8bb8-45251ba4ba9e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8fb95ef4-717f-4294-b7bf-56dea93f608c.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs92e1b072-9bf1-4006-a30e-45fb120ed605.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd99be36d-1b0d-4e10-9764-bd97dd1a129a.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs98a40295-c2fb-4d43-87b2-129dc6814c4c.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8164ff3d-087e-4eef-8faa-c3cd76ef46fd.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5e442af0-0ba5-4a7c-a02d-74990b0ad038.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs35f1efd9-f1e4-46c7-8ce4-1c2a2bbd67cb.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb4f9eb97-ac1d-487f-9bd7-4012f4866b41.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs072191c7-ac2c-4148-9bc6-e56787b456d7.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f9077c8-9cf1-4d15-aa0d-bb2cf240ee44.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3c7fc339-c225-4029-b478-8a5d2c8892d8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7437af62-d453-4e83-acaf-bdca194daffb.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd369ddfa-2921-4322-b07f-ea07b5a3efb3.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf18f3c4d-1993-45fe-8e44-eb235ed7f005.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs01008242-c1d2-4e63-980e-14ee317b3d5a.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs55ac9df9-6f19-44d5-8bf6-00d2e210d07c.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse6efa705-f104-483b-9afa-d5519b467b21.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs06e30e1b-8f23-4f7f-8fc6-1bd63da4b637.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs428da710-8156-4b1e-b663-389aba21e7e1.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs173169c8-ba5d-4cf2-b2c0-e217aa7cceb8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsed0363aa-03fd-407c-837c-9c16472778bc.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs83017bb0-ec50-4ea6-bfde-1e4ae0725989.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa8d39af1-693e-433a-aa6a-e8c14aa4d358.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf2e7b721-4473-42de-b754-05e8c3f5e350.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd506c047-c225-4ffd-b2f7-76b9419ddaa1.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse1647e6d-5e7f-4781-8d1d-a140cbc1ff48.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs22dbf0b6-72b0-4486-a9c7-ace0a016ef3b.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs12ca5fb8-870b-496f-91d0-a175233e1ad6.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs22bda1b0-e261-4d6b-98f8-fcb40dac2b51.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc4c226ca-9f71-4e3d-9182-38f5e84b2a78.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs465efa02-e045-457e-9ad0-139e8a7553b0.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsce414928-67cf-424f-8d4a-d700b6d216f6.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs57d02b25-963f-4bb1-951d-a22742324bfe.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4b8f00fa-e2cb-4ee7-8cca-99ba0809d09c.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs330af820-24c8-463a-a852-e65a52e7f407.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs701d95e5-1d2a-4cea-995a-2db7b0e18abf.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsff1694dd-6614-48e3-a38d-cb24a55a4880.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7f66c018-3ab9-44da-9b2b-42c2ae9a795d.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb1a759fb-f6f6-4325-9c21-912f7c562966.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs128a353d-e1e8-497c-b622-dae68aa8ccbe.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs09330029-262c-41a1-85d5-51ed7aff4546.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2bdb6ea4-4a6d-4623-acaa-f6317edf6fea.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f8f9156-983b-4b6d-ba9b-7e15b25b2494.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs11534e22-a555-4bfb-8c6f-7ef12ddce207.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbbde4cab-77f3-4b55-889e-32d1d91b63a7.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs67435269-ba42-4d57-aeff-696b937f183d.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3e72fbe7-13d5-4168-a20b-094f9dc4539e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4334e9f1-0c6d-4dcd-a8e9-caf39d38bd9c.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse9c13e61-ba71-4127-8e76-200a5d2b6172.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1e1bf8ed-aa3f-4438-be70-48e64cac6f39.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4f1f170-36cf-4138-b6d8-cd6994de04ce.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs741d01d0-8d1e-46bb-aaa8-06b9bff369a6.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbf033b63-341c-4764-a494-72c09d861178.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs61efd649-2f0c-4c92-af21-c570b6164ef5.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee50a7e5-cf0b-4d26-b7b4-50293a9ff83e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa70efa00-eeaf-4147-add1-534183e9011b.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs28f88301-82c5-4b34-b6e7-9165b5ec2386.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9ac696ed-006c-4a57-8251-24e0e6f02315.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7270d114-1a83-4c9b-8b3d-e9a38d8132f7.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbba01958-ff09-4161-ab9f-89dcba339fe8.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsccddca39-de1d-4fa2-a7dd-434fb6ef1d77.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf0a52679-2de7-4309-96dc-f2e957e2b8a4.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4954ce7e-4dca-48cb-b7d3-4d5c55ea3178.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb752c0bd-8cb1-4648-8fca-08e56c89e6ae.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6c0cf334-b896-472e-a251-b6e70409a201.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8f6b1329-47d5-4218-a6e0-caafd91e5451.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs551017c5-885c-4adf-8fea-f5854d6f63e7.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsffe878f2-f907-47a6-86a6-b950ed53bc06.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs176abc64-ed19-4f3b-a32d-ac73f11b18e6.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse410e22c-1901-4a6a-be07-72ebb1040996.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs045527c2-36e0-4e13-94d5-02db5bd7ec3f.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs73aec1d9-0863-4a7c-a5e3-dbe773066993.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs95a5e88a-2524-450d-8acd-2ad077d81d13.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs65697220-65f5-4a8f-938a-c9279634781e.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs68636b52-567e-42be-82fc-1105b9f348f3.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee9b91b7-194e-48ac-981a-867f2bd5d32d.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs72ef1e3e-60e9-40d6-96f0-d070044d57f2.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9185bddc-2b8d-483b-a61f-c114909b63f0.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs451e0f6c-ed8a-4d76-a00f-6b7817488a93.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs55acca66-d320-418a-8c08-0b1fea36724d.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse5796da9-2e67-43d9-9133-0ef6edd61cad.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8f19f2f3-fe3a-48ce-a03b-b59c86603303.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0aacc31b-6b73-457f-bd68-93ea30b28307.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\temp\~dfd183.tmp". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\temp\scan.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:15 PM: Warning: Failed to open file "c:\documents and settings\abha\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:15 PM: sqlcsk.vbs (ID = 185675)
3:15 PM: Found Trojan Horse: trojan downloader matcash
3:15 PM: mc-110-12-0000137.exe (ID = 246327)
3:15 PM: vvsninst.exe (ID = 74460)
3:16 PM: Warning: Failed to open file "c:\documents and settings\abha\application data\mozilla\firefox\profiles\ystxomhg.default\parent.lock". The process cannot access the file because it is being used by another process
3:20 PM: c:\program files\network monitor (ID = -2147459771)
3:20 PM: c:\program files\vvsn (3 subtraces) (ID = -2147480376)
3:21 PM: vvsn.exe (ID = 188685)
3:21 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || VVSN (ID = 0)
3:26 PM: File Sweep Complete, Elapsed Time: 00:19:33
3:26 PM: Full Sweep has completed. Elapsed time 00:36:32
3:26 PM: Traces Found: 436
3:27 PM: Processing Startup Alerts
3:27 PM: Allowed Startup entry: Autofix.exe
3:27 PM: Removal process initiated
3:28 PM: Quarantining All Traces: trojan downloader matcash
3:28 PM: Quarantining All Traces: dollarrevenue
3:29 PM: Quarantining All Traces: maxifiles
3:29 PM: Quarantining All Traces: zquest
3:29 PM: Quarantining All Traces: accoona toolbar
3:29 PM: Quarantining All Traces: command
3:29 PM: Quarantining All Traces: webtrendslive cookie
3:29 PM: Removal process completed. Elapsed time 00:01:57
3:35 PM: Program Version 4.5.9 (Build 709) Using Spyware Definitions 665
3:35 PM: | End of Session, Wednesday, April 26, 2006 |
********
2:46 PM: | Start of Session, Wednesday, April 26, 2006 |
2:46 PM: Spy Sweeper started
2:50 PM: Your spyware definitions have been updated.
2:50 PM: | End of Session, Wednesday, April 26, 2006 |




And here is my HJT

Logfile of HijackThis v1.99.1
Scan saved at 3:55:38 PM, on 4/26/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\VsMain.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\VVSN\VVSN.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\McAfee\McAfee VirusScan\AlogServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\abha\Desktop\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: ECCEBHCG - {2D3033ED-1E8A-1569-3317-1FDD6211340E} - C:\WINDOWS\System32\Dakgiood.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 1,605
Reputation: 'Stein is on a distinguished road 
Solved Threads: 104
Team Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Freeprodtb!!

 
0
  #9
Apr 27th, 2006
Arg, sorry we're jus getting to ya now.

Could ya post a more recent log?

Thanks.
Now if ya like the help ya could always raise our reputation...
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5
Reputation: abha is an unknown quantity at this point 
Solved Threads: 0
abha abha is offline Offline
Newbie Poster

Re: Freeprodtb!!

 
0
  #10
Apr 28th, 2006
hey no prob...actually my comp is workin pretty fine..just a lil slowwwwww


Logfile of HijackThis v1.99.1
Scan saved at 12:17:32 AM, on 4/29/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\VVSN\VVSN.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\abha\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: ECCEBHCG - {2D3033ED-1E8A-1569-3317-1FDD6211340E} - C:\WINDOWS\System32\Dakgiood.dll (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC