evidently...i know nothing about computers.
i'm having nothing but problems...
most recently AVAST deleted wininet.dll. i got a replacement so i could access the internet, or rather a friend did for me. i downloaded an add-on for ad-aware se to delete the VX2 virus. all seeeeemed fine. my biggest problem at the moment is svchost.exe sucking up 80%-100% CPU usage. someone said it was the "welcha worm" ? which i never heard of. could find no tool to take care of it, either.

in addition i'm getting 12 pop-ups at a time from things such as "morwillsearch" "yamsta" and even google.
i have ad-aware and avast, as recommended by this site, so far. i might have hi-jack this...somewhere.
overall, i'm totally lost. if anyone even feels like helping me they'd be a kindgarten teacher because i know nothing of computers, like i said.

help please!

Recommended Answers

All 15 Replies

Download HijackThis self-extracting zip version from here. Once downloaded, double click on the file & it will install into it's own, permanent folder.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.

Logfile of HijackThis v1.99.1
Scan saved at 10:23:10 AM, on 10/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system32\mdms.exe
C:\WINDOWS\System32\qsysqs2d.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SurfAccuracy\SAcc.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLServiceHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\ALLISON WADE\Desktop\hijackthis_sfx.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: AuroraHandlerObj Class - {4AA870AC-8427-42a4-B92E-ECD956197489} - C:\WINDOWS\AuroraHandler.dll (file missing)
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll (file missing)
O2 - BHO: (no name) - {64A86024-B83D-2F9F-D170-6D5509F52B47} - C:\WINDOWS\System32\xapc.dll (file missing)
O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} - C:\WINDOWS\system32\appwiz.dll
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\lqea9.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {9C5875B8-93F3-429D-FF34-660B206D897A} - C:\WINDOWS\System32\performent011.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\System32\qsysqs2d.exe DO0605
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Fast Home] C:\WINDOWS\system32\svcnvt.exe home
O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\RunOnce: [jw30cnm.exe] C:\WINDOWS\System32\jw30cnm.exe /k
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [WinFixer 2005] "C:\Program Files\WinFixer 2005\wfx5.exe" /min
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [jw30cnm.exe] C:\WINDOWS\System32\jw30cnm.exe /k
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM32\qsysqs2d.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} - http://downloads.shopathomeselect.com/adpepper/grinstall_ap1001.cab
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb028.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129012798000
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.zillabar.com/toolbar/bin/dwnldr.cab
O20 - Winlogon Notify: drct16 - drct16.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)
O21 - SSODL: B0EIIGFF - {1CBF63C9-4D7E-1E95-609A-1ADE4A8E41B8} - C:\WINDOWS\System32\Ekpeclkp.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\Program Files\STOPzilla!\szntsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Wowsers, lots of rubbish there.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml

Once in Safe Mode, please run Ewido, and do a full scan. During the scan it will prompt you to clean files, click OK.

Save the logfile from the scan. Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

first of all, thanks for everything so far...taking the time and what not.
i have no idea what this means (and it's not that i don't trust this process) but that was the slowest start-up, yet... and things seemed to be moving very very slowly. but...hey, i don't know.

here is the you know

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------


+ Created on:           6:32:06 AM, 10/12/2005
+ Report-Checksum:      9A9526AE


+ Scan result:


HKLM\SOFTWARE\Classes\CLSID\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0199DF25-9820-4bd5-9FEE-5A765AB4371E} -> Spyware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0199DF25-9820-4bd5-9FEE-5A765AB4371E}\TypeLib\\ -> Spyware.SearchUpgrader : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{d714a94f-123a-45cc-8f03-040bcaf82ad6} -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{26C23254-9C6C-48D8-8BF4-E629104E8B36}\TypeLib\\ -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06}\TypeLib\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\ProxyStubClsid32\\ -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid\\ -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Spyware.YourSiteBar : Cleaned with backup
HKLM\SOFTWARE\Dsi -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\MaxSpeed -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{640B39C1-D713-464F-92C3-75BD972B95EE} -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\CLSID -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{2cf0b992-5eeb-4143-99c0-5297ef71f444} -> Spyware.BrowserAid : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0199DF25-9820-4bd5-9FEE-5A765AB4371E} -> Spyware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{0656A137-B161-CADD-9777-E37A75727E78} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx\\.Owner -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SbCIe028.dll\\.Owner -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/SbCIe028.dll\\{640B39C1-D713-464F-92C3-75BD972B95EE} -> Spyware.SideStep : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/mfc42.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/msvcrt.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/olepro32.dll\\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\PSGuard.com -> Spyware.PSGuard : Error during cleaning
HKLM\SOFTWARE\PSGuard.com\PSGuard -> Spyware.PSGuard : Error during cleaning
HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard -> Spyware.PSGuard : Error during cleaning
HKLM\SOFTWARE\PSGuard.com\PSGuard\P.S.Guard\License -> Spyware.PSGuard : Cleaned with backup
HKLM\SOFTWARE\Upsf -> Spyware.Delfin : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Security -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Enum -> Spyware.iSearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Error during cleaning
C:\Documents and Settings\ALLISON WADE\Application Data\eetu.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun\RunOnce -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKCURun\RunOnceEx -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun\RunOnce -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\HKLMRun\RunOnceEx -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\StartMenuAllUsers -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\Autorun\StartMenuCurrentUser -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Application Data\PSGuard.com\P.S.Guard\BrowserObjects -> Spyware.PSGuard : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@2o7[1].txt[/email] -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wfkygjdzggoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wflicpd5scpa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkoulcpgepg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkyqnazsaqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjlygjdzkbow-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@abetterinternet[1].txt[/email] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@ad.yieldmanager[2].txt[/email] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@adopt.specificclick[2].txt[/email] -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@ads18.bpath[1].txt[/email] -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@advertising[2].txt[/email] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@atdmt[1].txt[/email] -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@burstnet[2].txt[/email] -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@casalemedia[1].txt[/email] -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@com[1].txt[/email] -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@cz3.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@cz4.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@cz5.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@cz7.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wfk4aldjeeo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wfmykhdzcgo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjkoamdjkap.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjkoooczghp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjliggcjmcp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjlismajcbp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjlyckczcdo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjmieidjkbp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjmiuiczmep.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjny-1gcpcb.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@e-2dj6wjnyagazsep.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@fastclick[2].txt[/email] -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@hypertracker[1].txt[/email] -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@image.masterstats[1].txt[/email] -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@mediaplex[1].txt[/email] -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@microsofteup.112.2o7[2].txt[/email] -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@paypopup[1].txt[/email] -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@pro-market[2].txt[/email] -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@rotator.adjuggler[2].txt[/email] -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@sales.liveperson[1].txt[/email] -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@servedby.advertising[1].txt[/email] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@shopathomeselect[1].txt[/email] -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@specificpop[1].txt[/email] -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@statse.webtrendslive[1].txt[/email] -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@trafic[1].txt[/email] -> Spyware.Cookie.Trafic : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@tribalfusion[1].txt[/email] -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@vip.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@vip2.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@www.burstbeacon[2].txt[/email] -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@www.burstnet[1].txt[/email] -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@www.myaffiliateprogram[1].txt[/email] -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiqjdjmbpqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4oldpseowidj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4kgczadpaudj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliunazsfqamdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnywjdjmepgidj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnywnd5afoasdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@yieldmanager[1].txt[/email] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Cookies\allison [email]wade@ysbweb[1].txt[/email] -> Spyware.Cookie.Ysbweb : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\!update.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\08vl.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\0LtCoI.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\0p5.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\0wf.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\1gep.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\3.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\3gwWT.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\3sYeHoU7a.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\4.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\4K.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\6Y2ycm.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\7hl4HpVo.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\9Bf.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\9iEBTziT.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\9Npod.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\9u6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\9Vuqm.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\A6fZU.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\aDydiz.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\AvWUfA.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\AXoO.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\bF6j.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\BKFeZBXg.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\bVS7ULC.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\cjt.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\CXGl.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\D.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\D98D0qH7S.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\d9C.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\dealhelper.exe -> TrojanDownloader.Agent.hw : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Dss.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\f3MhScYnK.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\faU5Z.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\FFcXvnHN.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\FKNrwrc2.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\fmmmNpvN.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\FtK.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\g.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\gF.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\hwhxi4k.sys -> Trojan.Kolweb.e : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\i3Yo.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Ibgh0.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\ibJcOqw4i.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\iG.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Irh.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\iSqGimv.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\JkICBAk0.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\JuzNvoJ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\KKfZl50z.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\L.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\lc2J0ATyN.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\le.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\lHNwj.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\lPSys5.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\M0D70.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\mFQ9Gn9z.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\MQMW6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\mxWloz7.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\N.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\nsdtmp09.dll -> Spyware.MetaDirect : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\odRR.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Oe7.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\OR4ui.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\p30G.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\PmQh.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Pw.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\R0YDg93cO.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\r4id5G.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\R8VYwt2UO.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\rgKuTq6s.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\rz.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\RzA5Bois.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\ssk3_b5.exe -> TrojanDropper.Small.qn : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\SwM.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\tAm.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\TDvyMv8ei.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\U.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\u57kUq7JS.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\U5Eq6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\uMOPpn6.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\Ve6KHBVGd.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\VoXVBpk.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\w.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\w181609.stub.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\w5qR6Bvdn.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\whS9.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\XB.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\xIgGy5R.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\XpgsNzH.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\xWqQJDLT.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\YKa5cy.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\yrkuuAJl.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\YU1g.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temp\yzfhNnKew.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\0804Q2XS\ibar[1].js -> TrojanDownloader.IstBar.ad : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\0804Q2XS\optimize[1].exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\0L6ZC527\001[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\EQQTLPSE\istrecover[1].exe -> TrojanDownloader.IstBar.ij : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\EQQTLPSE\nem220[1].dll -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\KPQROPU3\dealhelper[1].exe -> TrojanDownloader.Agent.hw : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\KPQROPU3\ysb[1].dll -> TrojanDownloader.IstBar.lv : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\NJ7L91O7\sidefind[1].exe -> TrojanDownloader.IstBar.jm : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\NJ7L91O7\ysb_prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\OMJFHMMR\uninstaller.prod.21sep2005.exe[1] -> Spyware.SurfAccuracy : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\UDE32BCT\bb[1].exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\UDE32BCT\istsvc[1].exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\ALLISON WADE\Local Settings\Temporary Internet Files\Content.IE5\ZQ4PBQDW\SAcc.prod.v1112.05oct2005.exe[1] -> Spyware.SurfAccuracy : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@abetterinternet[2].txt[/email] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@ad.yieldmanager[2].txt[/email] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@adopt.specificclick[2].txt[/email] -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@com[2].txt[/email] -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@cz5.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@hypertracker[1].txt[/email] -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@vip.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Cookies\leah [email]wade@yieldmanager[1].txt[/email] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Local Settings\Temp\hwhxi4k.sys -> Trojan.Kolweb.e : Cleaned with backup
C:\Documents and Settings\LEAH WADE\Local Settings\Temp\MediaAccessInstPack.exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ENIDAH4R\loadppc[1].exe -> TrojanDropper.Small.abx : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@112.2o7[2].txt[/email] -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@1shz2prbmdj6wvny-1sez2pra2dj6wjny-1lajicqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wflikgd5oloq-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wfliqhdjmkoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkougdpmeqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkyggdjwkqq-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjl4qhc5kgpg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmiqiajoaqa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmiwldjsapw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmykmd5mfog-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1gc5oapwsdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1gczogogudj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1gdzgboqudj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1icpkcoaqdj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1idzidqaydj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1lazccoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1majkgqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1mczmkogydj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1ndzeepasdj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnycjdjifoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnyehdjkdpg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnyggczocoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnywmczklpa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnywoczsloa-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@abetterinternet[1].txt[/email] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ad.adition[2].txt[/email] -> Spyware.Cookie.Adition : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ad.adocean[2].txt[/email] -> Spyware.Cookie.Adocean : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ad.yieldmanager[1].txt[/email] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ad1.clickhype[1].txt[/email] -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@adopt.specificclick[2].txt[/email] -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@adorigin[1].txt[/email] -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ads20.hyperbanner[1].txt[/email] -> Spyware.Cookie.Hyperbanner : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@adtrak[2].txt[/email] -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@affiliates.x10[2].txt[/email] -> Spyware.Cookie.X10 : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@burstnet[2].txt[/email] -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@com[2].txt[/email] -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz11.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz3.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz4.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz5.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz6.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz7.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz8.clickzs[1].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@cz9.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkicmcpgcp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkikncpwbo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkiopczgho.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkiuocjwlo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkiwidpmeq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkoshcpcep.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfkyknajchp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfliqnczcbp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wflisocpmdp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wflokicpkep.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfmiapcpcko.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wfmikpdjmfo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjk4oldpseo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjk4sgazolp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkoemcjmlo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkoglc5ihq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkokhazsco.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkokncjieo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkokpazsbp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkoqpczmko.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkosoajclq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkoukc5efo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyandpogq.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyejajsbo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyekazako.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyencjwlo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkygiczicp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyugc5eao.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjkyuhd5cfp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjl4sncjwfp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjliahc5wlo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjliqnazgbo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlismcjggo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlockcjmhp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjloehdjefo.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjloekdjwep.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlooidjaho.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlosiazsfo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlycmcjkdo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlygicjakp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlygjcjkhq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlyqndjwlp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjlywmcpaco.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjmiupajchq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjmycgazclp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjmyehd5wkp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjmyukcpalp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjny-1ldzeb.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyagazsep.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyapcjelp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyapd5mdo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnycgc5wdp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnycnc5ccp.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnycodzako.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnycpdzkdo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyejczmdq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyohcjseo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyoldjolp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyoldzolo.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyomc5ggo.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnyslc5igq.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnysnajwbp.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnywgajebo.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@e-2dj6wjnywodzsko.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@hypertracker[2].txt[/email] -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@image.masterstats[1].txt[/email] -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@ivwbox[2].txt[/email] -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@orf.oewabox[1].txt[/email] -> Spyware.Cookie.Oewabox : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@paypopup[2].txt[/email] -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@rotator.adjuggler[1].txt[/email] -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@sales.liveperson[2].txt[/email] -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@shopathomeselect[2].txt[/email] -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@trafficcenter[1].txt[/email] -> Spyware.Cookie.Trafficcenter : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@vip.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@vip2.clickzs[2].txt[/email] -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@www.belstat[2].txt[/email] -> Spyware.Cookie.Belstat : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@www.burstbeacon[2].txt[/email] -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@www.burstnet[1].txt[/email] -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@www.epilot[1].txt[/email] -> Spyware.Cookie.Epilot : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@www.myaffiliateprogram[1].txt[/email] -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4cnc5wdowqdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4ekdjmcpqudj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4wgdpgdoqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4whc5kkogsdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiaicjekow2dj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkicidzeeoq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkikncpwbogwdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiqgczicpq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkockc5maqawdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoghc5okoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkokmcpikoa6dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoupd5iloaidj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkowhdpodpwsdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyaldjwkqasdj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkychd5efowidj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyejczacpq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyejdjggpqwdj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyqoazkcpqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wfliqpdjwepqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wflokjd5oloaqdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4cicjabogudj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ehc5sfowqdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ghajokoawdj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4koazolpqwdj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4oldpseowidj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4opczelqaidj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4qkd5gdoq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4qnc5mepg6dj6x9ny-1seq-2-2.stats.esomniture[1].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ugazmgqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt[/email] -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\STEPHEN WADE\Cookies\stephen [email]wade@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4upaj

Your turn for the 'wowsers' when you see what you have to do next :mrgreen:

Can you please do the following.

===============

Go to Add/Remove programs and remove(uninstall) the following, if present:

PSGuard

The above could appear anywhere within the entry. Be careful not to remove any personal or system software.

===============

Now, let's open a command prompt by going to the start menu and then select 'Run'.

In the box that pops up type in 'cmd'. The command prompt will open.

OR

You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the dll(s) we're going to remove, by entering the following:

regsvr32 /u appwiz.dll

It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save typing them in.

===============

Run HiJackThis, click "Scan", then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.172/index.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway

R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)

O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: AuroraHandlerObj Class - {4AA870AC-8427-42a4-B92E-ECD956197489} - C:\WINDOWS\AuroraHandler.dll (file missing)
O2 - BHO: (no name) - {64A86024-B83D-2F9F-D170-6D5509F52B47} - C:\WINDOWS\System32\xapc.dll (file missing)
O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} - C:\WINDOWS\system32\appwiz.dll
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\lqea9.dll (file missing)
O2 - BHO: (no name) - {9C5875B8-93F3-429D-FF34-660B206D897A} - C:\WINDOWS\System32\performent011.dll (file missing)

O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Fast Home] C:\WINDOWS\system32\svcnvt.exe home
O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [WinFixer 2005] "C:\Program Files\WinFixer 2005\wfx5.exe" /min
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM32\qsysqs2d.exe

O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)

O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} - http://downloads.shopathomeselect.c...tall_ap1001.cab

O20 - Winlogon Notify: drct16 - drct16.dll (file missing)
O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)

O21 - SSODL: B0EIIGFF - {1CBF63C9-4D7E-1E95-609A-1ADE4A8E41B8} - C:\WINDOWS\System32\Ekpeclkp.dll (file missing)


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

folders...

C:\Program Files\SurfSideKick 3
C:\Program Files\P.S.Guard
C:\Program Files\SurfAccuracy
C:\Program Files\WinFixer 2005

files...

C:\WINDOWS\system32\appwiz.dll
C:\WINDOWS\system32\svcnvt.exe
C:\WINDOWS\SYSTEM32\qsysqs2d.exe

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

To help protect your system from hostile ActiveX content, or special 'downloadable' files:

Download, install and keep updated, SpywareBlaster. If you've installed it for the first time:

1) Check for any available updates; if present, they'll be automatically downloaded and installed.
2) Next, "Enable all protection".
3) Exit the program.

-

Note: Remember to regularly check for updates.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

alright alright...things seem to be running better, though i have no better understanding of computers. it's not lightning fast, but this computer is no spring chicken. now...the new log, and a couple of questions.

Logfile of HijackThis v1.99.1
Scan saved at 1:12:30 AM, on 10/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLHostManager.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\1123871960\ee\AOLServiceHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/180solutions/ie/bridge-c282.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129012798000
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.zillabar.com/toolbar/bin/dwnldr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\Program Files\STOPzilla!\szntsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


a couple of things about the last step...
doing this...regsvr32 /u appwiz.dll
i got this error : regsvr21 (error) appwiz.dll was loaded, but the DllUnregisterserver entry point was not found. this file can not be registered.

yea, i don't know. also, i thought i had closed all instances of explorer...evidently, not. as i got an error trying to delete the BHO files. which are still apparent...how do i close ALL explorer(s) and i definetly want to get rid of that viewpoint toolbar. and the stopzilla warnings, the program used to work, but now i just get errors about the copy being suspended.

lastly (probably not) you made the mistake of being friendly and helpful, so a couple of questions...
i have no idea what a registry key is, but when i run ad-aware...there is over 1100 registry keys (working? running?) is this normal?
2. i had an error where i couldn't defrag, but haven't tried again, yet.
so let me know about the bho's and how to get rid of viewpoint, and stopzilla, please? if you don't mind.

with spyware blaster, ewido, ad-aware, avast...i'm pretty protected, then? not a lot of chance my computer getting this bad, again?

thanks SO much for everything, so far.

Can you please do the following.

===============

Go to Add/Remove programs and remove(uninstall) the following, if present:

Viewpoint Toolbar

The above could appear anywhere within the entry. Be careful not to remove any personal or system software.

===============

Next, Open a command prompt by:

1. Clicking "Start", then "Run...".
2. Enter "cmd" (without the quotes).
3. Enter "services.msc" (without the quotes).

-

Now, locate and 'stop' the following services, if present:

STOPzilla Local Service - International Software Systems Solutions ... (C:\Program Files\STOPzilla!\szntsvc.exe)

Look carefully, since the name of the service (above) can be anywhere in the entry; also be careful not to 'stop' any required system services. Once stopped, set this service to disabled.

===============

Run HiJackThis then:

1. Click "Open the Misc Tools Section"
2. Click "Open Process manager"

-

Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

C:\Program Files\STOPzilla!\szntsvc.exe

Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.

===============

Still in HiJackThis, click "Scan", then check(tick) the following, if present:


O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll

O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun

O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/1...bridge-c282.cab

O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\Program Files\STOPzilla!\szntsvc.exe


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

(To do this, just hit the 'X' on any Internet Explorer windows that are open. Even this one. Check in Task Manager for iexplore.exe and end process of each of them))

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

folders...

C:\Program Files\STOPzilla!
C:\Program Files\Viewpoint

files...

C:\WINDOWS\System32\SZIEBHO.dll

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

==

Browsing habits also affect how your computer's health will be :).
Most apps on your PC will be referenced to in the registry in order for them to work as they should. Also a place you do not want to mess with if you know nothing about it :).

sorry this step took so long... spent a bit of time in denver. i did notice, however... by the time i got back. i had psguard...again. i repeated the steps from before and it seems to be gone. how does one make it through the rest of their days without ever having to see it again? i notice that ewido has...stopped showing up? from my little tray.
overall, the computer seems to be running much more rapido. i did get one error, after my screen went blue blue blue. about...unable to run dll as app? or something to that affect. not much else... but here's the newest.

Logfile of HijackThis v1.99.1
Scan saved at 8:42:37 AM, on 10/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdService] C:\WINDOWS\System32\AdService.dll
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129012798000
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.zillabar.com/toolbar/bin/dwnldr.cab
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axinstall/SRInstall4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

The trial period for Ewido would have run out and now the real-time protection is disabled. Ewido will still update and remove pests though.

Can you please do the following.

===============

Run HiJackThis, click "Scan", then check(tick) the following, if present:


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

O4 - HKLM\..\Run: [AdService] C:\WINDOWS\System32\AdService.dll

O20 - Winlogon Notify: winwea32 - C:\WINDOWS\SYSTEM32\winwea32.dll


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

files...

C:\WINDOWS\System32\AdService.dll
C:\WINDOWS\SYSTEM32\winwea32.dll

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

Ok i know this is an old post, and i respect that but i am having a problem with winwea32.dll even in safe mode i cannot delete it, do you have any ideas? heres a log from ewido


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 4:49:19 PM, 3/30/2006
+ Report-Checksum: 64DF55CC

+ Scan result:

HKLM\SOFTWARE\Classes\MEDIATICKETSINSTALLER.MediaTicketsInstallerCtrl.1 -> Adware.PurityScan : Error during cleaning
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaTickets -> Adware.PurityScan : Cleaned with backup
[240] C:\WINNT\system32\winwea32.dll -> Downloader.Small.cml : Error during cleaning
C:\WINNT\Downloaded Program Files\MediaTicketsInstaller.ocx -> Adware.MediaTickets : Cleaned with backup
C:\WINNT\mtuninst.exe -> Adware.MediaTickets : Cleaned with backup
C:\WINNT\system32\dfrgsrv.exe -> Trojan.Small : Cleaned with backup
C:\WINNT\system32\ginuerep.dll -> Trojan.Small : Cleaned with backup
C:\WINNT\system32\oins.exe -> Downloader.PurityScan.bt : Cleaned with backup
C:\WINNT\system32\Мicrosoft.NET\attrib.exe -> Downloader.PurityScan.by : Cleaned with backup
C:\WINNT\temp\edlmhdmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINNT\temp\win1935.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINNT\temp\win6D5.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINNT\temp\win6DC.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@educationsuccess.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@interchangecorporation.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup


::Report End

Hi, Please download HJT.

Download hijackThis. Extract it to its own folder. Then run it and select, Do system scan and save log. Post the contents of the log that pops up.

Please start your own thread next time...

Thanks.

ok i am sorry, and next time i will, normally i do not bring back old posts from anywhere but this is the only thing i could find with the same problems. i did finally get the winwea cleaned but now im having a prob with a registry key,here is the log from hjt

Logfile of HijackThis v1.99.1
Scan saved at 5:22:42 PM, on 3/30/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINNT\runservice.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Common Files\F?nts\m?config.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe


O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [Hiac] "C:\DOCUME~1\ADMINI~1\APPLIC~1\YSTEM3~1\regedit.exe" -vt mt
O4 - HKCU\..\Run: [Jimjz] C:\Program Files\Common Files\F?nts\m?config.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: FreshDownload - {823CF9D7-3C2D-4FF9-ABAD-227BCA8724BC} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123828377921
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=5071
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{65133CE5-8E74-46DD-9367-B91F54EA822E}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{65133CE5-8E74-46DD-9367-B91F54EA822E}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{65133CE5-8E74-46DD-9367-B91F54EA822E}: NameServer = 192.168.1.1
O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)
O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUICECooLSrv.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINNT\runservice.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


and a new log from ewido
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------


+ Created on:           5:11:26 PM, 3/30/2006
+ Report-Checksum:      C6AD07A6


+ Scan result:


HKLM\SOFTWARE\Classes\MEDIATICKETSINSTALLER.MediaTicketsInstallerCtrl.1 -> Adware.PurityScan : Error during cleaning
[204] C:\WINNT\system32\winwea32.dll -> Downloader.Small.cml : Cleaned with backup
C:\WINNT\system32\winwea32.dll -> Downloader.Small.cml : Cleaned with backup



::Report End

Hi, run HJT again, and check these items.


O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll

O4 - HKCU\..\Run: [Hiac] "C:\DOCUME~1\ADMINI~1\APPLIC~1\YSTEM3~1\regedit.exe" -vt mt

O4 - HKCU\..\Run: [Jimjz] C:\Program Files\Common Files\F?nts\m?config.exe

O9 - Extra button: FreshDownload - {823CF9D7-3C2D-4FF9-ABAD-227BCA8724BC} - C:\Program Files\FreshDevices\FreshDownload\fd.exe

O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazz....cab?refid=1123

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTic....cab?refid=5071

O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)

O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)

Close all browsers and click Fix Checked

-----------------------------------------------------

Then delete this file.

C:\Program Files\Common Files\F?nts\m?config.exe

Then this folder.

C:\Program Files\Common Files\F?nts

----------------------------------------------------

Then please download CCleaner - www.ccleaner.com - Install it, run it and let it clean.

----------------------------------------------------

You are going to want to uninstall MessengerPlus 3! using Add/Remove Programs.

Usually this comes with a Lop Infection.


Please post a new log, when done...

i think someone hijacked my thread...heh heh
anyway, i saw the topic reply notification, and decided it was time for a checkup. plus i have a few concerns.
should i have started a new thread or kept it personal, and stick to this one, though it is old.

my newest concern, aside from my computer running painfully slow, is... psguard. it will NOT go away. other than those 2, my computer has been amazing, thanks to you guys. here is my logfile, and i had just run an ewido scan that nabbed "psguard" and 19 or so other files (i lost the logfile) minutes later the adaware SE scan found... low and behold, PSGUARD! and THIRTY other objects. so at the bottom is an excerpt from Adaware's scan. i'll get an ewido logfile if you need it.

Logfile of HijackThis v1.99.1
Scan saved at 2:26:03 PM, on 4/13/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {E278209A-BF27-B6DE-7B95-BC9EFC3757CA} - C:\WINDOWS\System32\recufyfz.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [fkwbg.exe] C:\WINDOWS\System32\fkwbg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [yaemu.exe] C:\WINDOWS\System32\yaemu.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129012798000
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4642/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{54073110-24A0-4593-A4A8-73ED5C793859}: NameServer = 85.255.116.78,85.255.112.227
O17 - HKLM\System\CCS\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 85.255.116.78,85.255.112.227
O17 - HKLM\System\CS1\Services\Tcpip\..\{54073110-24A0-4593-A4A8-73ED5C793859}: NameServer = 85.255.116.78,85.255.112.227
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Malware.Psguard Object Recognized!
Type : File
Data : A0100400.dll
TAC Rating : 7
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP631\

Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0100401.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP631\

oh yea, and that last one with a TAC? rating of 10.
so, how's she lookin?

i appreciate any help or advice, you guys have been insanely helpful, so far. but, of course, no rush. remember, it is running dreadfully slow.

thanks again and again and.. in the future?

This thread has been brought up, and "Hijacked" by others a few times, perhaps you should start a fresh one? Thats what I would do :).

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.