HOW do I "close all open browser windows"??!

The only (legitimate) browser I'm using is Internet Explorer, and it's already closed; cable modem switched off; every other program closed. How do I find the "open browser windows"?

When I try to clean my internet cache, I always get a message that "one or more browser windows are open", and presumably whatever sneakies are responsible for this are exactly what I want HJT to remove. Will it be able to remove them even if they are holding some secret window open?

Here's my first HJT log. I ran BHO Demon, Spybot and AdAware already, but most of the junk (Ibis Toolbar, etc.) refuses to stay deleted.

Logfile of HijackThis v1.99.1
Scan saved at 2:59:03 PM, on 8/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\System32\cdm34786.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\avwav950.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\m?dtc.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Documents and Settings\Eman\My Documents\Anti-Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50196
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sandiego.cox.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50196
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50196
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MyQuickSearch Search Assistant BHO - {04011C11-2F3B-44ed-977C-270CA669C6B2} - C:\Program Files\MyQuickSearch\SrchAstt\1.bin\MQSSRCAS.DLL (disabled by BHODemon)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06E60DAB-BE49-C1EB-18C2-E6BC1F7ABA9A} - C:\WINDOWS\system32\htzk.dll (disabled by BHODemon)
O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (disabled by BHODemon)
O2 - BHO: (no name) - {39CA3832-878D-FC75-8D59-DA7F631DD5C7} - C:\WINDOWS\system32\luafbi.dll (disabled by BHODemon)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (disabled by BHODemon)
O2 - BHO: (no name) - {B3F9AD3C-44DF-6D73-892E-4DE60A8D5A9F} - C:\WINDOWS\System32\ylnecelh.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Workflow] D:\Workflow.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [4a38992e95f2] C:\WINDOWS\System32\cdm34786.exe
O4 - HKLM\..\Run: [vjUn2] C:\documents and settings\rogelio\local settings\temp\vjUn2.exe
O4 - HKLM\..\Run: [Eu41tz] C:\documents and settings\rogelio\local settings\temp\Eu41tz.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [da407c58abde] C:\WINDOWS\System32\avwav950.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [vjUn2.exe] C:\documents and settings\rogelio\local settings\temp\vjUn2.exe
O4 - HKLM\..\Run: [Eu41tz.exe] C:\documents and settings\rogelio\local settings\temp\Eu41tz.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Icst] C:\Documents and Settings\Eman\Application Data\spos.exe
O4 - HKCU\..\Run: [Yyxv] C:\WINDOWS\System32\m?dtc.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks a million for any help you can offer.

Recommended Answers

All 6 Replies

Hi,
Download Ewido and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.

Download CCleaner and install it.


Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options (Folder Option will be in View Menu in Win98).
Uncheck Hide protected operating system files.
Then, click to select the option Show hidden files and folders.
Click Apply and then click OK to exit.


Reboot in Safe Mode:-
Restart (or switch ON) the PC.
Then, keep tapping the F8 Key.
From the menu that will be displayed, out of which choose Safe Mode and press Enter.


Uninstall this Software from Add/Remove Programs in Control Panel:-
ViewPoint ToolBar (or ViewPoint Manager)


Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50196
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sandiego.cox.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50196
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50196
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MyQuickSearch Search Assistant BHO - {04011C11-2F3B-44ed-977C-270CA669C6B2} - C:\Program Files\MyQuickSearch\SrchAstt\1.bin\MQSSRCAS.DLL (disabled by BHODemon)
O2 - BHO: (no name) - {06E60DAB-BE49-C1EB-18C2-E6BC1F7ABA9A} - C:\WINDOWS\system32\htzk.dll (disabled by BHODemon)
O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (disabled by BHODemon)
O2 - BHO: (no name) - {39CA3832-878D-FC75-8D59-DA7F631DD5C7} - C:\WINDOWS\system32\luafbi.dll (disabled by BHODemon)
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (disabled by BHODemon)
O2 - BHO: (no name) - {B3F9AD3C-44DF-6D73-892E-4DE60A8D5A9F} - C:\WINDOWS\System32\ylnecelh.dll (file missing)
O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [4a38992e95f2] C:\WINDOWS\System32\cdm34786.exe
O4 - HKLM\..\Run: [vjUn2] C:\documents and settings\rogelio\local settings\temp\vjUn2.exe
O4 - HKLM\..\Run: [Eu41tz] C:\documents and settings\rogelio\local settings\temp\Eu41tz.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [da407c58abde] C:\WINDOWS\System32\avwav950.exe
O4 - HKLM\..\Run: [vjUn2.exe] C:\documents and settings\rogelio\local settings\temp\vjUn2.exe
O4 - HKLM\..\Run: [Eu41tz.exe] C:\documents and settings\rogelio\local settings\temp\Eu41tz.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKCU\..\Run: [Icst] C:\Documents and Settings\Eman\Application Data\spos.exe
O4 - HKCU\..\Run: [Yyxv] C:\WINDOWS\System32\m?dtc.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll

Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.


Exit from HijackThis. Delete these files:-
C:\WINDOWS\System32\cdm34786.exe
C:\WINDOWS\System32\avwav950.exe
C:\WINDOWS\System32\m?dtc.exe
C:\WINDOWS\system32\htzk.dll
C:\WINDOWS\system32\luafbi.dll
C:\WINDOWS\System32\ylnecelh.dll
C:\Documents and Settings\Eman\Application Data\spos.exe
C:\WINDOWS\System32\m?dtc.exe
C:\WINDOWS\System32\maxspeed.exe

Delete these folders:-
C:\PROGRAM FILES\Toolbar
C:\Program Files\MyQuickSearch
C:\Program Files\Viewpoint


Run CCleaner:-

  • Click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours".
  • Click OK to exit from the Options.
  • Finally click "Run Cleaner" and click "OK" to continue cleaning.

Run Ewido:-

  • Click on the "Scanner" button in the left menu, then click on the "Start" button.
  • If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  • When the scan finishes, click on "Save Report". This will create a text file.

Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log along with the Ewido log.

Thanks a million. I'll do it tonight. Wish me luck.

Cheers,
E.Ramos

Okay, Ewido ran for an hour and a half and identified 384 objects. Here's the log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------


+ Created on:           3:25:07 AM, 8/15/2005
+ Report-Checksum:      197116E1


+ Scan result:


HKLM\SOFTWARE\Classes\CLSID\{0E677229-E309-4341-81BD-3CC3018BF5B3} -> Spyware.MyQuickSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2C4E6D22-B71F-491F-AAD3-B6972A650D50} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{310CC549-4541-46A9-940F-52B342A6E682} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{69357D4E-BF4D-4651-91E9-52ECD45A0128} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6E21F428-5617-47F7-AED8-B2E1D8FBA711} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{708BE496-E202-497B-BC31-9CF47E3BF8D6} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8B0FA130-0C3D-4CB1-AEB7-2C29DA5509A3} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BBF122A7-8A4D-45B5-9E00-0F68BC87C904} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CAE0999F-78C5-49DC-9F30-13142AAAABA4} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1616B86-9288-489D-B71A-0CCF2F1A89DA} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FF76A5DA-6158-4439-99FF-EDC1B3FE100C} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{234F09FB-FE89-4C6D-9203-31832FC051C3} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{365B9A54-E613-46E5-9DB1-4F91A9DE80BD} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{618BE527-B7F5-417C-BC51-98FDC2D6DE61} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{66C22569-F05C-4A70-A142-763B337E1002} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{7B8BD940-B1EF-460C-85A2-9ACAAF7F9303} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{99AA88D1-D9D3-410A-BE9E-044F94C183DA} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C380566D-F343-42AB-987B-6B38A1A35747} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D1951679-1D52-43FC-9585-0737143585F5} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F273D4EA-2025-4410-8408-251A0CD46BE7} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res\toolbar.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginConfig -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginConfig\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDown -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDown\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginEvents -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginEvents\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginInst -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginInst\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginServer -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginServer\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\toolbar.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\toolbar.ResProtocol\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{37AC49E3-E906-4BD8-AE83-D0F7FB48FD17} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{B23B3ADD-84B1-414A-92B9-0CABE5A781F4} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\MaxSpeed -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\toolbar -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\toolbar\Install -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E677221-E309-4341-81BD-3CC3018BF5B3} -> Spyware.MyQuickSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04011C11-2F3B-44ED-977C-270CA669C6B2} -> Spyware.MyQuickSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E677221-E309-4341-81BD-3CC3018BF5B3} -> Spyware.MyQuickSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E677229-E309-4341-81BD-3CC3018BF5B3} -> Spyware.MyQuickSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{120E090D-9136-4B78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} -> Spyware.LinkReplacer : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841} -> Spyware.MidAddle : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-299502267-507921405-1343024091-1007\Software\toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@a.shopathomeselect[1].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@ehg-nestleusainc.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@shopathomeselect[2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@web4.realtracker[2].txt -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@www.shopathomeselect[2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Noel\Cookies\noel@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\Cookies\noel@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\Cookies\noel@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\Cookies\noel@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\ts.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~355208.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~358889.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~387478.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~394778.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~435393.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~490002.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~548541.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~643760.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~646657.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~651243.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~665223.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~665919.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~672300.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~712026.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~718124.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~719659.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~743897.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~795364.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~802596.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~902959.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~903568.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Noel\Local Settings\Temp\~947900.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@ad.yieldmanager[3].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@coxhsi.112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@ehg-coxcommunications.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@shopathomeselect[2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Rogelio\Cookies\rogelio@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\1F.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\25.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\3s.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\3uLjE0.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\5ItfnhXn.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\6U.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\6UAl7OxW.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\8D.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\8D1.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\9dna.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\An7ky.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\b5NdgJ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\BqrcbSef.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\CLuUb9.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\CMeTVbCAF.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\cUQ1x.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\d9.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\dgD5b.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\ehelNDAMb.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\eouU.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\EWlbCV6Zs.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\EwQm712I9.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\f.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\F1rLyX1GJ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\f81620ha.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\fLg6GQA.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\fNQD6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\gJ7WIMPpq.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\H.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\HB.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\hBL.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\hSCdkrO8.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\IB272.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\iephX95D.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Ir8P.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\iYy.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\j2OOR6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\jGzdULxt.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\K08GQA9hg.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\kpBRvP.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\L2EpXAss.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\L4oTQwS.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\ltIrqR.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\MmKQktSTr.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\NOVU61ot.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\o3.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Oeo.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\OIbGLyk.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Pag.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\pfjNC.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\PxyfMgn.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\qQt.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Qx4.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\rkf.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\RVZ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\rwF.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\ScgwofzU.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Se6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Sm.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\TBT.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\tgbB.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\UJv1G.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\V.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\V6i5j.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Vku.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Wk.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\wszlFbGV.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\X31Q5dV2K.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\xEZOpXj.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\XkSUc.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\Y3.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\YGGXQ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\yGmUr3NHu.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\zlzXdUIYz.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~304158.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~307402.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~389171.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~399758.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~553330.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~668768.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~776517.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~881891.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~893772.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~904338.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~908615.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~922218.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Rogelio\Local Settings\Temp\~954573.tmp -> Spyware.Wintools : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\TBPS3630.BUD/Program Files/Toolbar/TBPSSvc.exe -> Spyware.WebSearch : Error during cleaning
C:\RECYCLER\NPROTECT\00000205.TXT -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000206.TXT -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\RECYCLER\NPROTECT\00000207.TXT -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000208.TXT -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\RECYCLER\NPROTECT\00000209.TXT -> Spyware.Cookie.Advertising : Cleaned with backup
C:\RECYCLER\NPROTECT\00000211.TXT -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\RECYCLER\NPROTECT\00000212.TXT -> Spyware.Cookie.Advertising : Cleaned with backup
C:\RECYCLER\NPROTECT\00000213.TXT -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\RECYCLER\NPROTECT\00000214.TXT -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\RECYCLER\NPROTECT\00000236.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000238.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000239.TXT -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\RECYCLER\NPROTECT\00000241.TXT -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\RECYCLER\NPROTECT\00000243.TXT -> Spyware.Cookie.Overture : Cleaned with backup
C:\RECYCLER\NPROTECT\00000274.wzg -> Spyware.IBIS : Cleaned with backup
C:\RECYCLER\NPROTECT\00000286.rmr -> Spyware.IBIS : Cleaned with backup
C:\RECYCLER\NPROTECT\00000287.wzg -> Spyware.WebSearch : Cleaned with backup
C:\RECYCLER\NPROTECT\00000288.wzg -> Spyware.IBIS : Cleaned with backup
C:\RECYCLER\NPROTECT\00000308.wzg -> Spyware.IBIS : Cleaned with backup
C:\RECYCLER\NPROTECT\00000339.TXT -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\NPROTECT\00000340.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000343.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000353.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000358.TXT -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\RECYCLER\NPROTECT\00000366.TXT -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\RECYCLER\NPROTECT\00000369.TXT -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\RECYCLER\NPROTECT\00000393.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000394.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000395.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000413.TXT -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000414.TXT -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000417.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000418.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000419.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000420.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000423.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000428.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000429.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000430.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000431.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000434.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000435.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000436.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000437.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000438.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000439.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000454.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000455.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000456.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000457.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000458.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000459.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000460.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000462.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000463.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000464.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000471.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000472.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000473.TXT -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\NPROTECT\00000474.TXT -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\RECYCLER\NPROTECT\00000477.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000485.TXT -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\RECYCLER\NPROTECT\00000486.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000487.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000488.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000489.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000490.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000491.TXT -> Spyware.Cookie.Revenue : Cleaned with backup
C:\RECYCLER\NPROTECT\00000492.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000493.TXT -> Spyware.Cookie.Adserver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000498.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000499.TXT -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\RECYCLER\NPROTECT\00000515.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000517.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000518.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000519.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000520.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000521.TXT -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\RECYCLER\NPROTECT\00000531.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000532.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000533.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000534.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000535.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000536.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000537.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000538.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000539.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000540.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000541.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000542.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000543.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000544.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000545.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000546.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000547.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000548.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000549.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000550.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000551.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000552.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000553.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000554.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000555.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000556.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000557.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000558.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000559.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000562.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000563.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000564.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000565.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000566.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000567.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000568.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000569.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000570.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000571.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000572.TXT -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\RECYCLER\NPROTECT\00000573.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000575.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000576.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000577.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000578.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000579.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000585.TXT -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\RECYCLER\NPROTECT\00000601.CAB/newmajorse2.txt -> Spyware.WebSearch : Error during cleaning
C:\RECYCLER\NPROTECT\00000612.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000613.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000614.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000615.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000616.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000617.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000635.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000636.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000637.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000638.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000639.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000663.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000664.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000665.TXT -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\NPROTECT\00000725.exe -> Spyware.IEDriver : Cleaned with backup
C:\RECYCLER\NPROTECT\00000758.exe -> Spyware.UrlSpy : Cleaned with backup
C:\RECYCLER\NPROTECT\00000763.EXE -> TrojanDownloader.PurityScan.k : Cleaned with backup
C:\WINDOWS\system32\actxprxy.exe -> Spyware.AdSrve : Cleaned with backup
C:\WINDOWS\system32\atitvo32.exe -> Spyware.AdSrve : Cleaned with backup
C:\WINDOWS\system32\avifil32.exe -> Spyware.AdSrve : Cleaned with backup
C:\WINDOWS\system32\bitsprx2.exe -> Spyware.UrlSpy : Cleaned with backup
C:\WINDOWS\system32\аttrib.exe -> Spyware.PurityScan : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@gm.preferences[1].txt[/email] -> Spyware.Cookie.Preferences : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ads.link4ads[1].txt[/email] -> Spyware.Cookie.Link4ads : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ads.link4ads[3].txt[/email] -> Spyware.Cookie.Link4ads : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ads.link4ads[4].txt[/email] -> Spyware.Cookie.Link4ads : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ads.link4ads[2].txt[/email] -> Spyware.Cookie.Link4ads : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@www.popuptraffic[1].txt[/email] -> Spyware.Cookie.Popuptraffic : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ehg-espn.hitbox[2].txt[/email] -> Spyware.Cookie.Hitbox : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ehg-sportsline.hitbox[4].txt[/email] -> Spyware.Cookie.Hitbox : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ehg-dig.hitbox[4].txt[/email] -> Spyware.Cookie.Hitbox : Cleaned with backup
F:\WINDOWS\Cookies\eman [email]ramos@ehg-dig.hitbox[7].txt[/email] -> Spyware.Cookie.Hitbox : Cleaned with backup
F:\WINDOWS\Temporary Internet Files\Content.IE5\AS52CJTA\house_list[1].htm -> Spyware.BookedSpace : Cleaned with backup
F:\WINDOWS\Temporary Internet Files\Content.IE5\SXUNKPUV\pup[2].html -> Trojan.NoClose.c : Cleaned with backup



::Report End


I restarted in normal mode and ran HJT again, and this is what I've got:


Logfile of HijackThis v1.99.1
Scan saved at 3:28:32 AM, on 8/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\ati2sgag.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sandiego.cox.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Workflow] D:\Workflow.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thank you so very much for your help. I look forward to learning what do do next.

G'night.
E.Ramos

Hi,
Log looks clean :)

When I try to clean my internet cache, I always get a message that "one or more browser windows are open"

Do you receive the above mentioned error? Please check this, and post back the results.

:D It's CLEAN, CLEAN, CLEAN! No more trouble. Wow, you guys are amazing! Thank you again.

E.Ramos

p.s. I've reset my restore point and upped the security settings on my web browser, but if anything manages to get in again, I now have the tools to deal with it. Thanks.

Hi,
Good :D Glad that we could help you. I will mark this thread as "Solved" :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.