Ok Im a newbie but with searching for help for my problem I came across this forum..thank god! I seem to be having the same problem as everyone else with these popups. I did try and get rid of this but with mine I notice that when you end the process it changes its name...there are tons of them. so heres my log. help please!!

Logfile of HijackThis v1.99.1
Scan saved at 11:43:40 PM, on 7/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\AIM95\aim.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
c:\windows\system32\iqkcvb.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office 2000\Office\OUTLOOK.EXE
C:\Documents and Settings\Default\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [jinblm] c:\windows\system32\iqkcvb.exe r
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mpnnln.exe reg_run
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Global Startup: pitt.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install031.exe
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.media-motor.net/cabs/diamond.cab
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

Recommended Answers

All 11 Replies

I hope its ok to bump :o

Hi Jessykah, welcome to DaniWeb :D

Yes, it's okay to 'bump' but please wait a bit longer before doing so. I realize you'r anxious to get your computer fixed, but there are only a few of us here trying to resolve dozens of users problems, and we can't be here all the time. I'd say that if you don't get a response within 24 hrs to go ahead and give it a bump to make sure it isn't being overlooked.

Please follow the recommendations in these threads to help protect and start the cleanup process of your system:

http://www.daniweb.com/techtalkforums/thread27519.html

http://www.daniweb.com/techtalkforums/thread27570.html

Then close any open broswer windows, scan with hijackthis, and post a new log and wait for instructions on removing the Aurora infection and anything else remaining.

okie dokies heres my new log.

Logfile of HijackThis v1.99.1
Scan saved at 5:57:41 PM, on 7/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\AIM95\aim.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
c:\windows\system32\iqkcvb.exe
C:\AIM95\aim.exe
C:\WINDOWS\System32\mpnnln.exe
C:\Documents and Settings\Default\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [jinblm] c:\windows\system32\iqkcvb.exe r
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mpnnln.exe reg_run
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install031.exe
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.media-motor.net/cabs/diamond.cab
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

You will need to disconnect from the internet so you may wish to print these instructions.

Download Ewido Security Suite from here:
http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1

Install and update it, and then close the program (don't scan yet).

Download Nailfix from here:
http://www.noidea.us/easyfile/file.php?download=20050515010747824
Unzip it to your desktop, but do not run it yet.

Remove Newdotnet either from Add/Remove Programs, or by following the instructions here:
http://www.newdotnet.com/removal.html

Also in Add/Remove Programs, remove quickbar, if present.

Download, install, update, and run these tools:

CWShredder -- http://www.intermute.com/spysubtract/cwshredder_download.html
about:Buster -- http://www.majorgeeks.com/download4289.html
HSRemove -- http://www.majorgeeks.com/download4286.html
PurityScan uninstaller -- http://www.purityscan.com/uninstall.html

Disconnect from the net and reboot into Safe Mode.

Double-click on the Nailfix.cmd that is on your desktop. Your desktop and icons will disappear and reappear, and a window should open and close very quickly -- this is normal.

Then run a full system scan with Ewido (note: you will be posting the log from this scan in your next reply).

Still in Safe Mode, scan with hijackthis and have it fix the following entries:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://approvedlinks.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O4 - HKLM\..\Run: [jinblm] c:\windows\system32\iqkcvb.exe r
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mpnnln.exe reg_run
C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\PROGRA~1\INTERN~1\Toolbar\toolbar.hta
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - http://www.2nd-thought.com/files/install031.exe
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.media-motor.net/cabs/diamond.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

Go to the following locations and delete the highlighted files:

C:\WINDOWS\Nail.exe
C:\windows\system32\iqkcvb.exe
C:\WINDOWS\System32\mpnnln.exe
c:\windows\SvcProc.exe

Do a search for these files and delete any instances found:

quickbar.dll
toolbar.hta

Empty your Recycle Bin and reboot normally.

Close any open browser windows, scan with HJT and post a new log along with the Ewido log.

ok here is my new hjt log

Logfile of HijackThis v1.99.1
Scan saved at 4:34:21 PM, on 7/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\AIM95\aim.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Documents and Settings\Default\Desktop\Hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [xbnsrhy] c:\windows\system32\avaxrc.exe r
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

and my ewido log

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------


+ Created on:           4:01:03 PM, 7/10/2005
+ Report-Checksum:      48401F0C


+ Scan result:


HKLM\SOFTWARE\Classes\AdAgent.AdvertisementAgent -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.AdvertisementAgent\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.BannerListItem -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.BannerListItem\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.CompositeItem -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.CompositeItem\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.SpotListItem -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\AdAgent.SpotListItem\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\BTGrabDll.BTGrabDllObj -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\BTGrabDll.BTGrabDllObj\CLSID -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\BTGrabDll.BTGrabDllObj\CurVer -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CeresDll.CeresDllObj -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CeresDll.CeresDllObj\CLSID -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CeresDll.CeresDllObj\CurVer -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{08E05EEE-5EE9-11D4-9CAF-00D0B76063FD} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{11032FC2-C2F4-11D3-AD67-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{11032FC2-C2F5-11D3-AD67-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{28F00B04-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{28F00B0F-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.BroadCastPC : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{28F00B20-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{28F00B21-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{315FFE67-CEBE-11D3-AD70-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5CA9D47F-4BBC-45E0-815F-670AE736A678} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5DCDE22E-E64F-11D3-AD74-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5DCDE22E-E650-11D3-AD74-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{80F1B906-D066-11D3-AD70-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AD7084-90AD-11D4-813D-00500487B1C5} -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BCDDAB74-C3A8-11D3-AD69-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C357398A-8E21-4505-8BD7-784A4E9AC659} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C357398B-8E21-4505-8BD7-784A4E9AC659} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C357398C-8E21-4505-8BD7-784A4E9AC659} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Hiwire.Register -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Hiwire.Register\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Hiwire.Register\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdPlayer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdPlayer\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdPlayer\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdScheduler -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdScheduler\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AdScheduler\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AudioPlayers -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AudioPlayers\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.AudioPlayers\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RadioPlayers -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RadioPlayers\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RadioPlayers\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RealAdPlayer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RealAdPlayer\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RealAdPlayer\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RREventManager -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RREventManager\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWAdInsertion.RREventManager\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWWebPlayer.WebPlayer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWWebPlayer.WebPlayer\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\HWWebPlayer.WebPlayer\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{244D13BB-AFDB-11CE-85D1-00AA00695286} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{39341EB6-C340-4F68-AB9D-EE4917309828} -> Spyware.AdRotator : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{3E4BCF50-865B-4EF4-A0BC-BF57229EA525} -> Spyware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{4BB35A55-A91A-11CF-BA7C-00A0D1001A5A} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{59EBB576-CEB0-42FA-9917-DA6254A275AD} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{64A5BD22-8D8A-4193-9CF8-7DB5212ABB17} -> Spyware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6B1BE803-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6B1BE807-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9F61CFDF-5C79-4D35-B4DA-766B28367223} -> Spyware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B88A3AF1-4F1B-4400-8FFB-3FCB108CE115} -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{E832FFDE-8ED2-47B7-BE50-729A238040A0} -> Spyware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F2A97FA2-714D-11CF-BA24-00A0D1001A5A} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\RMActiveX.RMPlayer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\RMActiveX.RMPlayer\CLSID -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\RMActiveX.RMPlayer\CurVer -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{08E05EE1-5EE9-11D4-9CAF-00D0B76063FD} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{6B1BE80A-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{78A163D2-2358-464D-807B-0E2A078C7727} -> Spyware.MediaMotor : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{8E0D8965-B97B-468D-8306-A05929E439C1} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{96B2D8D3-E66D-11D3-AD74-009027B8ADBC} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{C094876D-1B0E-46FA-B6A6-7FFC0F970C27} -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{EAC42C32-1FE3-4FD0-9F27-E7F9CCF5FCD9} -> Spyware.AdRotator : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{EDC2D623-4D9E-4C3E-843F-74B1B2429B43} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{F5EE52D3-2ECC-409E-A92F-A73F2B8DD407} -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Hiwire -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Hiwire\Hiwire -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Hiwire\Hiwire\2.1.5 -> Spyware.HiWire : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{13197ACE-6851-45C3-A7FF-C281324D5489} -> Spyware.2nsSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E0CE16CB-741C-4B24-8D04-A817856E07F4} -> Spyware.Roimoi : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Netsetter -> Spyware.MarketScore : Cleaned with backup
HKLM\SOFTWARE\Netsetter\OSMIM -> Spyware.MarketScore : Cleaned with backup
HKLM\SOFTWARE\PowerScan -> Spyware.PowerScan : Cleaned with backup
HKLM\SOFTWARE\SDS Software -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\SDS Software\Setup2Go -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\SDS Software\Setup2Go\UserData -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\slmss -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2 -> Spyware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2\Internet Explorer -> Spyware.SurfSide : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT -> Spyware.NaviSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Security -> Spyware.NaviSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Enum -> Spyware.NaviSearch : Cleaned with backup
HKU\.DEFAULT\Software\Brilliant Digital Entertainment -> Spyware.BrilliantDigital : Cleaned with backup
HKU\.DEFAULT\Software\Brilliant Digital Entertainment\PROJECTOR -> Spyware.BrilliantDigital : Cleaned with backup
HKU\.DEFAULT\Software\Brilliant Digital Entertainment\PROJECTOR\GUI -> Spyware.BrilliantDigital : Cleaned with backup
HKU\.DEFAULT\Software\Brilliant Digital Entertainment\PROJECTOR\lensquest3s -> Spyware.BrilliantDigital : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Browser -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Faceplate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Gate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\History -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\History\Log -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Player -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Presets -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\REGISTRATION -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Resources -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\Stations -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\StationSelection -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\eMachines\WebUpdate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MEDIAMANAGER -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MEDIAMANAGER\HISTORY -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MEDIAMANAGER\REPORT -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Browser -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Faceplate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Gate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\History -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\History\Log -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Presets -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Registration -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Resources -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Stations -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\StationSelection -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\WebUpdate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1123561945-842925246-1202660629-1004\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\Brilliant Digital Entertainment -> Spyware.BrilliantDigital : Cleaned with backup
HKU\S-1-5-18\Software\Brilliant Digital Entertainment\PROJECTOR -> Spyware.BrilliantDigital : Cleaned with backup
HKU\S-1-5-18\Software\Brilliant Digital Entertainment\PROJECTOR\GUI -> Spyware.BrilliantDigital : Cleaned with backup
HKU\S-1-5-18\Software\Brilliant Digital Entertainment\PROJECTOR\lensquest3s -> Spyware.BrilliantDigital : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Browser -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Faceplate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Gate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\History -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\History\Log -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Player -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Presets -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\REGISTRATION -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Resources -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\Stations -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\StationSelection -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\eMachines\WebUpdate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MEDIAMANAGER -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MEDIAMANAGER\HISTORY -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MEDIAMANAGER\REPORT -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Browser -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Faceplate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Gate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\History -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\History\Log -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Presets -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Registration -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Resources -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\Stations -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\StationSelection -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Hiwire\MusicMatch\WebUpdate -> Spyware.HiWire : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Explorer Bars\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} -> Spyware.CometCursor : Cleaned with backup
[1204] VM_00970000 -> Adware.BetterInternet : Error during cleaning
C:\WINDOWS\SYSTEM\UpdInstall.exe -> Spyware.VX2 : Cleaned with backup
C:\WINDOWS\SYSTEM\Comet\Temp\suSigned.exe/fclnk.exe -> Spyware.CometCursor : Cleaned with backup
C:\WINDOWS\SYSTEM\Comet\Temp\suSigned.exe/cstray.exe -> Spyware.CometCursor : Cleaned with backup
C:\WINDOWS\SYSTEM32\sfinsth.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\raigfxf.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\pvsetupd.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\sentprfe.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\jao.dll -> TrojanSpy.Briss.h : Cleaned with backup
C:\WINDOWS\SYSTEM32\boidnak.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\SYSTEM32\tracea.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\hrggngg.dll -> TrojanDownloader.Qoologic.q : Cleaned with backup
C:\WINDOWS\SYSTEM32\im6am.dll/bi.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\SYSTEM32\im6am.dll/biprep.exe -> Trojan.Bispy.B : Cleaned with backup
C:\WINDOWS\SYSTEM32\lmf32.dll -> Spyware.Hyperlinker : Cleaned with backup
C:\WINDOWS\SYSTEM32\oqppip.dll -> TrojanDownloader.Qoologic.e : Cleaned with backup
C:\WINDOWS\SYSTEM32\okshook.dll -> Spyware.Netsetter : Cleaned with backup
C:\WINDOWS\SYSTEM32\randreco.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\SYSTEM32\osmim.dll -> Spyware.MarketScore : Cleaned with backup
C:\WINDOWS\SYSTEM32\deluxnetwork.exe -> TrojanSpy.Briss.h : Cleaned with backup
C:\WINDOWS\SYSTEM32\rmooxoo.exe -> TrojanDownloader.Qoologic.q : Cleaned with backup
C:\WINDOWS\SYSTEM32\exdl1.exe -> Adware.eXact : Cleaned with backup
C:\WINDOWS\SYSTEM32\pudds.dll -> TrojanDownloader.Qoologic.q : Cleaned with backup
C:\WINDOWS\SYSTEM32\mpnnln.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/exdl.exe -> Adware.eXact : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/msexreg.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\exul1.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\SYSTEM32\redit.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\SYSTEM32\llhostd.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\ctivedsa.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\bdusk.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\tis.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\igverifs.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\ritew.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\msss.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\shatmw.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\p43dmodm.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\atimed.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\ClrSchP017.exe -> Backdoor.Ruledor.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\mcompata.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\SYSTEM32\IEHelperMiddleMan.dll -> Spyware.Bonzo : Cleaned with backup
C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar : Cleaned with backup
C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\pss\pitt.exeCommon Startup -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\bdl84126.exe -> Trojan.Revop.c : Cleaned with backup
C:\WINDOWS\pup.exe -> TrojanDownloader.Vb.ca : Cleaned with backup
C:\WINDOWS\btstvam.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\HyperLinker.exe -> Spyware.iSearch : Cleaned with backup
C:\WINDOWS\MSVXD.EXE -> Worm.Datom : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\install.exe -> Trojan.SecondThought.ac : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\thin.exe -> TrojanDownloader.Infamous : Cleaned with backup
C:\WINDOWS\ups.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\farmmext.exe -> Spyware.ConsCorr : Cleaned with backup
C:\WINDOWS\actulice.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\stdinternet.exe -> TrojanSpy.Briss.h : Cleaned with backup
C:\WINDOWS\shizzyp.exe -> Trojan.Revop.b : Cleaned with backup
C:\WINDOWS\UnstSA5.exe -> TrojanDropper.Delf.z : Cleaned with backup
C:\WINDOWS\LastGood\System32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\LastGood\System32\exdl.exe -> Adware.eXact : Cleaned with backup
C:\WINDOWS\LastGood\System32\exul.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\LastGood\webhdll.dll -> Spyware.WebHancer : Cleaned with backup
C:\WINDOWS\LastGood\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\LastGood\farmmext.exe -> Spyware.ConsCorr : Cleaned with backup
C:\WINDOWS\LastGood\BTGrab.dll -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\qool.exe -> TrojanDropper.Small.kz : Cleaned with backup
C:\WINDOWS\xcopy.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\istinstall_si.exe -> TrojanDownloader.Small.gl : Cleaned with backup
C:\WINDOWS\jawa32.ocx -> Spyware.Suggestor : Cleaned with backup
C:\WINDOWS\LastGood.Tmp\System32\ATPartners.dll -> TrojanDownloader.Rameh.c : Cleaned with backup
C:\WINDOWS\Wrapper.exe -> TrojanDropper.Small.nm : Cleaned with backup
C:\WINDOWS\jawa32.exe -> Spyware.Suggestor : Cleaned with backup
C:\WINDOWS\ikuudbn.exe -> Backdoor.Agent.bg : Cleaned with backup
C:\WINDOWS\launchurl.exe -> Trojan.Zapchast : Cleaned with backup
C:\WINDOWS\vufhkajiw.exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\themexp\Themexp.org File\TBEZA127Q.exe -> Spyware.Quick : Cleaned with backup
C:\Program Files\BearShare\Installer\saveinstwm.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\wnmngm1.exe -> TrojanDownloader.Ultimx.a : Cleaned with backup
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\rdvs.exe -> TrojanDownloader.Ultimx.b : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\pitt.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Documents and Settings\Default\Desktop\Programs.rar/Style XP\start.exe -> TrojanDropper.Bridge : Error during cleaning
C:\Documents and Settings\Default\Desktop\eclsxp3q.zip/start.exe -> TrojanDownloader.IstBar : Error during cleaning
C:\Documents and Settings\Default\Cookies\default@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@ads18.bpath[1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@www.paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@www6.paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@www1.paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@www3.paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Default\Cookies\default@edge.ru4[4].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
->  : Error during cleaning
:mozilla.89:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.350:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.351:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.452:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.453:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.455:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.456:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\u09tfgmu.Jessica\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
->  : Error during cleaning
:mozilla.80:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btcem50t.Jess\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\btce

Getting better, just look at all the stuff Ewido cleaned for you :)

You should follow the instructions here (again):
http://www.daniweb.com/techtalkforums/thread27570.html

Update your antivirus program and allow it to fix whatever it finds.

Scan with HJT and have it fix the following entries:

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [xbnsrhy] c:\windows\system32\avaxrc.exe r
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Remember to close any open window before hitting Fix checked.

Go to the following locations and delete the highlighted files:

C:\WINDOWS\wupdt.exe
C:\windows\system32\avaxrc.exe

Do a search for the following files and delete any instances found:

Systb.dll
Winobject.dll
Winserv.exe
Wupdt.exe

If any of files cannot be deleted in normal mode, try Safe Mode.

Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.

Empty your Recycle Bin and reboot.

Close any open browser windows, scan with HJT, and post a new log please.

thank you so much for your help!! =D

Logfile of HijackThis v1.99.1
Scan saved at 9:47:14 PM, on 7/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\AIM95\aim.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Documents and Settings\Default\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

I don't see anything else, are you still having problems? If so, please give us specific details :)

thank you so much =) no im not having any more problems! i really appreciate your help! thanks tons! :mrgreen:

thank you so much =) no im not having any more problems! i really appreciate your help! thanks tons! :mrgreen:

Great! Glad to hear it :)
Happy computing!

This thread is now closed. If you need it reopened, please send a PM to one of our Mods.

Include the link to the thread and detail why you need it reopened.

If this is not your thread please start a New Topic.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.