This problem started earlier today. A pop-up told me i ahd spyware and i have run several programs and everything has been cleaned. My screen is whie, and i cannot change it to anything... I have unchekced all boxes in the 'customise desktop' and have run hijackthis and these were the results.


Logfile of HijackThis v1.99.1
Scan saved at 9:34:47 PM, on 12/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\OasClnt.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCEvtHdlr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Ares\Ares.exe
C:\Program Files\Interwise\Student\pull.exe
D:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\78RIWHXI\stng259[1].exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\DOCUME~1\Chris\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yc.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yc...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yc...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Trillian.lnk = D:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\Interwise\Student\pull.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\system32\PhnxCDSvr.exe

any ideas on how to fix this?

Recommended Answers

All 5 Replies

Hi titan5239, welcome to DaniWeb :)

Unfortunately, everything has not been cleaned, but before proceeding with the fixes, there is one thing you need to take care of first:

C:\DOCUME~1\Chris\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

The log entry above indicates that you are running HijackThis from within a Temp/Temporary folder. Please do the following:
Create a folder for HJT outside of any Temp/Temporary folders and move the HijackThis.exe file to that folder now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if HijackThis (and other data that you care about) is living in those Temp folders, it will be erased along with everything else!
Temp/Temporary folders are just that- Temporary. They are not meant for permanent storage, as their contents are often delete in the course of troubleshooting, by running disk clean-up utilities, etc.

-------------------------------------------------------------------------------------------------
Once you've taken care of the above:

You will need to close/quit all web browser programs and disconnect from the Internet for much of the following, so you should print out these instructions or save them into a text file with Notepad.

1. Download and install these utilities (but do not run scans with them yet):

ewido Security Suite (trial version) - http://www.ewido.net/en/download/
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
Ad Aware SE Personal - http://www.lavasoftusa.com/
SpyBot Search & Destroy - http://www.safer-networking.org/

- Open ewido. In the main screen, click "Update" and click "Start Update". After the update process completes, exit from Ewido.

- Open MS Antispyware beta. Make sure the "AntiSpyware Autoupdater" feature is enabled, and that it has downloaded the most current antispyware updates. Close the program after you've verified this.

- Open SpyBot and use its update feature to download and install the most current spyware definitions file. Close the program once the update is complete.

- Open AdAware, click the "Check for updates now" button, and follow the prompts to install the most current spyware definition database. Close the program once the update is complete.

- Open McAfee and use its Update feature to make sure that you have the most current virus definitions installed. As with the above programs, don't run a scan with it; just close it once it is updated.


3. Download and install the CCleaner utility, but don't run it yet.


4. Run HijackTHis again, put a check mark next to the following entries, and then click the "Fix checked" button. Close HJT once it has finished performing its fixes:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

5. Reboot into Safe Mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up).


6. Run CCleaner. It may take a while for the program to perform its cleaning, so be patient. Close the program when it has finished.


7. Run McAfee, SpyBot, ewido, AdAware, and MS Antispyware beta consecutively; have the programs fix all malicious items they find.

When ewido finds the first malicious object on your system, it will ask you if it should clean it. When it asks this, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
Save the log file that ewido will create after it finishes scanning; you'll be including that log in your next post here.


8. Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".

- Delete the c:\secure32.html file if it still exists.


9. Empty your Recycle Bin, reboot normally, run HijackThis again, and post the new log. Also post the log that ewido generated.

THANK YOU SOO MUCH!!!!!!! I HAVE MY DESKTOP BACK!! i lost all of my desktop pictures, but i can get those back! Here are the logs.

HijackThis:


Logfile of HijackThis v1.99.1
Scan saved at 4:51:28 PM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCEvtHdlr.exe
C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
D:\Program Files\Trillian\trillian.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\DOCUME~1\Chris\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Trillian.lnk = D:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1135728077\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\system32\PhnxCDSvr.exe



AND ewido:


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------


+ Created on:           4:14:38 PM, 12/30/2005
+ Report-Checksum:      8E53F36D


+ Scan result:


HKLM\SOFTWARE\Classes\Interface\{CABBB49A-4D7B-415B-8250-15C3B854E9FF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject -> Spyware.FizzleBar : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CLSID -> Spyware.FizzleBar : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CurVer -> Spyware.FizzleBar : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@data4.perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@ehg-lionsgate.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@ehg-tigerdirect2.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@reduxads.valuead[2].txt -> Spyware.Cookie.Valuead : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@server.iad.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@test.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Chirs2\Cookies\chirs2@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Chirs2\Local Settings\Temporary Internet Files\Content.IE5\11CKKKBE\MediaGateway[1].exe -> Adware.WinAD : Cleaned with backup
C:\Documents and Settings\Chirs2\Local Settings\Temporary Internet Files\Content.IE5\WCCVV2V6\bridge-c24[1].cab/MediaGatewayX.dll -> Adware.WinAD : Cleaned with backup
C:\Program Files\MediaGateway\MediaGateway.exe -> Adware.WinAD : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Adware.WinAD : Cleaned with backup
C:\winstall.exe -> Not-A-Virus.Hoax.Win32.Renos.aj : Cleaned with backup
D:\WINDOWS\Downloaded Program Files\gsda.dll -> Dialer.Generic : Cleaned with backup
D:\WINDOWS\Temporary Internet Files\Content.IE5\HBP0Q0RE\mm[1].js -> Spyware.Chitika : Cleaned with backup
D:\WINDOWS\Cookies\chris@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\WINDOWS\Cookies\chris@findwhat[1].txt -> Spyware.Cookie.Findwhat : Cleaned with backup
D:\WINDOWS\Cookies\chris@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@hg1.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@spylog[2].txt -> Spyware.Cookie.Spylog : Cleaned with backup
D:\WINDOWS\Cookies\chris@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
D:\WINDOWS\Cookies\chris@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
D:\WINDOWS\Cookies\chris@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
D:\WINDOWS\Cookies\chris@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-idg.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@adviva[1].txt -> Spyware.Cookie.Adviva : Cleaned with backup
D:\WINDOWS\Cookies\chris@cz6.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
D:\WINDOWS\Cookies\chris@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\WINDOWS\Cookies\chris@sales.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
D:\WINDOWS\Cookies\chris@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
D:\WINDOWS\Cookies\chris@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
D:\WINDOWS\Cookies\chris@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-nokiafin.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
D:\WINDOWS\Cookies\chris@7search[2].txt -> Spyware.Cookie.7search : Cleaned with backup
D:\WINDOWS\Cookies\chris@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\WINDOWS\Cookies\chris@ad-logics[1].txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
D:\WINDOWS\Cookies\chris@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
D:\WINDOWS\Cookies\chris@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
D:\WINDOWS\Cookies\chris@excite[2].txt -> Spyware.Cookie.Excite : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wfkowgdzekp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-sixapart.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
D:\WINDOWS\Cookies\chris@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
D:\WINDOWS\Cookies\chris@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter9.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter.hitslink[2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
D:\WINDOWS\Cookies\chris@xxxcounter[2].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@cz8.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
D:\WINDOWS\Cookies\chris@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
D:\WINDOWS\Cookies\chris@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
D:\WINDOWS\Cookies\chris@stat.onestat[2].txt -> Spyware.Cookie.Onestat : Cleaned with backup
D:\WINDOWS\Cookies\chris@as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\WINDOWS\Cookies\chris@sexlist[1].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
D:\WINDOWS\Cookies\chris@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter6.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@ws.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-interlifeform.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@twci.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
D:\WINDOWS\Cookies\chris@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\WINDOWS\Cookies\chris@pro-market[1].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjny-1id5og.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjk4omdzmlo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter7.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter8.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter3.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-directv.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@gamingpromo[1].txt -> Spyware.Cookie.Gamingpromo : Cleaned with backup
D:\WINDOWS\Cookies\chris@goldenpalace[1].txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
D:\WINDOWS\Cookies\chris@banner.goldenpalace[2].txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
D:\WINDOWS\Cookies\chris@cityclub.gamingpromo[2].txt -> Spyware.Cookie.Gamingpromo : Cleaned with backup
D:\WINDOWS\Cookies\chris@www.goldenpalace[1].txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
D:\WINDOWS\Cookies\chris@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
D:\WINDOWS\Cookies\chris@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
D:\WINDOWS\Cookies\chris@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
D:\WINDOWS\Cookies\chris@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-shoes.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjkoojczohq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-penguingroupusa.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
D:\WINDOWS\Cookies\chris@paycounter[2].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
D:\WINDOWS\Cookies\chris@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
D:\WINDOWS\Cookies\chris@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\WINDOWS\Cookies\chris@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehealthcaresolutions.122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
D:\WINDOWS\Cookies\chris@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-dig.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@server.iad.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjkyukajoep.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjny-1ocpgf.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@e-2dj6wjkysncpmep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
D:\WINDOWS\Cookies\chris@sel.as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-fandango.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@valueclick[3].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\WINDOWS\Cookies\chris@statse.webtrendslive[1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
D:\WINDOWS\Cookies\chris@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
D:\WINDOWS\Cookies\chris@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-attworldnet.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\WINDOWS\Cookies\chris@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
D:\WINDOWS\Cookies\chris@a.as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\WINDOWS\Cookies\chris@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-bestbuy.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
D:\WINDOWS\Cookies\chris@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
D:\WINDOWS\Cookies\chris@fastclick[3].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@z1.adserver[3].txt -> Spyware.Cookie.Adserver : Cleaned with backup
D:\WINDOWS\Cookies\chris@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
D:\WINDOWS\Cookies\chris@citi.bridgetrack[3].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
D:\WINDOWS\Cookies\chris@revenue[3].txt -> Spyware.Cookie.Revenue : Cleaned with backup
D:\WINDOWS\Cookies\chris@sexlist[2].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
D:\WINDOWS\Cookies\chris@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
D:\WINDOWS\Cookies\chris@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter9.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter7.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@counter2.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
D:\WINDOWS\Cookies\chris@statse.webtrendslive[3].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
D:\WINDOWS\Cookies\chris@excite[3].txt -> Spyware.Cookie.Excite : Cleaned with backup
D:\WINDOWS\Cookies\chris@trafficmp[3].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\WINDOWS\Cookies\chris@fastclick[4].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-attworldnet.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-dig.hitbox[3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-ignitemedia.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@www.burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
D:\WINDOWS\Cookies\chris@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
D:\WINDOWS\Cookies\chris@sonycorporate.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-sonycomputer.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@tradedoubler[3].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
D:\WINDOWS\Cookies\chris@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
D:\WINDOWS\Cookies\chris@adopt.specificclick[3].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@fl01.ct2.comclick[2].txt -> Spyware.Cookie.Comclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
D:\WINDOWS\Cookies\chris@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\WINDOWS\Cookies\chris@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
D:\WINDOWS\Cookies\chris@hitbox[3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@ads.pointroll[3].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
D:\WINDOWS\Cookies\chris@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
D:\WINDOWS\Cookies\chris@bs.serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\WINDOWS\Cookies\chris@bluestreak[3].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
D:\WINDOWS\Cookies\chris@www.burstbeacon[3].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
D:\WINDOWS\Cookies\chris@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup
D:\WINDOWS\Cookies\chris@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\WINDOWS\Cookies\chris@edge.ru4[3].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
D:\WINDOWS\Cookies\chris@ads.addynamix[3].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
D:\WINDOWS\Cookies\chris@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\WINDOWS\Cookies\chris@data4.perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
D:\WINDOWS\Cookies\chris@servedby.advertising[3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\WINDOWS\Cookies\chris@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
D:\WINDOWS\Cookies\chris@yieldmanager[3].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
D:\WINDOWS\Cookies\chris@valueclick[4].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
D:\WINDOWS\Cookies\chris@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-ifilm.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@ehg-warnerbrothers.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\WINDOWS\Cookies\chris@rotator.adjuggler[2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
D:\WINDOWS\Cookies\chris@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
D:\My Documents\MsgPlus-301.exe/sponsor.exe -> Downloader.Swizzor.ag : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50D4.TMP -> Spyware.Cookie.2o7 : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50D5.TMP -> Spyware.Cookie.2o7 : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50E3.TMP -> Spyware.Cookie.Specificclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50E4.TMP -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50E5.TMP -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50F0.TMP -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50F1.TMP -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq50F4.TMP -> Spyware.Cookie.Bfast : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5100.TMP -> Spyware.Cookie.Bfast : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5102.TMP -> Spyware.Cookie.Bluestreak : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5103.TMP -> Spyware.Cookie.Bluestreak : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5105.TMP -> Spyware.Cookie.Burstnet : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5110.TMP -> Spyware.Cookie.Casalemedia : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5112.TMP -> Spyware.Cookie.Casalemedia : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5113.TMP -> Spyware.Cookie.Centrport : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5114.TMP -> Spyware.Cookie.Centrport : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5122.TMP -> Spyware.Cookie.Bridgetrack : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5125.TMP -> Spyware.Cookie.Clickagents : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5131.TMP -> Spyware.Cookie.Com : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5132.TMP -> Spyware.Cookie.Comclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5134.TMP -> Spyware.Cookie.Pro-market : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5136.TMP -> Spyware.Cookie.Coremetrics : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5144.TMP -> Spyware.Cookie.Doubleclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5150.TMP -> Spyware.Cookie.Doubleclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5151.TMP -> Spyware.Cookie.Ru4 : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5153.TMP -> Spyware.Cookie.Ru4 : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5155.TMP -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5162.TMP -> Spyware.Cookie.Falkag : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5164.TMP -> Spyware.Cookie.Falkag : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5166.TMP -> Spyware.Cookie.Fastclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5171.TMP -> Spyware.Cookie.Fastclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5175.TMP -> Spyware.Cookie.Gator : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5181.TMP -> Spyware.Cookie.Gator : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5183.TMP -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5185.TMP -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5191.TMP -> Spyware.Cookie.Hitbox : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51A2.TMP -> Spyware.Cookie.Mediaplex : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51A4.TMP -> Spyware.Cookie.Mediaplex : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51B4.TMP -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51C0.TMP -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51C2.TMP -> Spyware.Cookie.Paypopup : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51C4.TMP -> Spyware.Cookie.Qksrv : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51D0.TMP -> Spyware.Cookie.Questionmarket : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51D3.TMP -> Spyware.Cookie.Questionmarket : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51E1.TMP -> Spyware.Cookie.Realtracker : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51E3.TMP -> Spyware.Cookie.Revenue : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51E5.TMP -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51F2.TMP -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq51F4.TMP -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5200.TMP -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5205.TMP -> Spyware.Cookie.Spylog : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5211.TMP -> Spyware.Cookie.Onestat : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5214.TMP -> Spyware.Cookie.Targetnet : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5220.TMP -> Spyware.Cookie.Targetnet : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5224.TMP -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5231.TMP -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5233.TMP -> Spyware.Cookie.Tribalfusion : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5240.TMP -> Spyware.Cookie.Tribalfusion : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5245.TMP -> Spyware.Cookie.Valueclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5252.TMP -> Spyware.Cookie.Valueclick : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5263.TMP -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5270.TMP -> Spyware.Cookie.Adserver : Cleaned with backup
D:\Program Files\Yahoo!\YPSR\Quarantine\ppq5272.TMP -> Spyware.Cookie.Adserver : Cleaned with backup
D:\Program Files\Messenger Plus! 3\Setup.dat/sponsor.exe -> Downloader.Swizzor.ag : Cleaned with backup



::Report End

Looks good- there are no signs of infections in your latest HJT log. :)

Does everything seem to be working properly now?

yes, wonderfully, thank you soo much!!!

Oh, by the way, it was wierd, because i created another username on my computer, and that one never got infected...

Anyway, thanks again!

Glad we could help. Have a happy, spyware-free New Year! :)

...it was wierd, because i created another username on my computer, and that one never got infected...

Actually, that's not such a weird thing, because spyware infections aren't generally designed to spread in the way that viruses do. Spyware definitely can infect a computer in ways that effect all users, but it's equally possible for the infefction to be confined only to the particular user account which is active at the time the spyware is installed.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.