Author Topic: pop-ups and memory error  (Read 2991 times)

Offline shawnpgorman

  • Newbie
  • *
  • Posts: 2
  • Karma: +0/-0
    • View Profile
pop-ups and memory error
« on: August 08, 2005, 12:33:18 AM »
I have been having problems with pop-ups. I have run avg, adaware, and spybot sd. This has fixed most of the problems, but I am still getting a few pop-ups and when I open programs I get the following error message. The Instruction at "0x732e7800" referenced memory at "0x732e7800". The memory could not be read. so long as I don't click on anything I can use the program but if I click on ok or cancel it crashes the program. here is a current hijackthislog:

Logfile of HijackThis v1.99.1
Scan saved at 1:31:46 AM, on 8/8/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\cusrvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\system32\NALNTSRV.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\TIREMOTE\wuser32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\dpmw32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\NWTRAY.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\etb\pokapoka62.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Cassetica\Cassetica NotesMedic Pro\NMPSystray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\beckerri\My Documents\programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://insite.nytco.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.shopnav.com/sidesearch.cgi?uid=&id=1.20030
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NDPS] C:\WINNT\system32\dpmw32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [service] C:\WINNT\services.exe -serv
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINNT\system32\n20050308.EXE
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NMPSystray.lnk = C:\Program Files\Cassetica\Cassetica NotesMedic Pro\NMPSystray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1123288439704
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1123288421458
O17 - HKLM\System\CCS\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O20 - Winlogon Notify: Setup - C:\WINNT\system32\n22u0cf9ef2.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Track-It! Remote Control (TIRmtCtl) - Intuit Track-It! - C:\WINNT\TIREMOTE\wuser32.exe
O23 - Service: Track-It! Workstation Manager (TIRmtSvc) - Intuit, Inc. - C:\WINNT\TIREMOTE\TIRemoteService.exe

any help would be appreciated.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
pop-ups and memory error
« Reply #1 on: August 08, 2005, 07:51:16 PM »
Let's see if you can run these tools in safe mode

==Download and then Install
Ewido Security Suite

When installing, under "Additional Options" Uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We'll fix that later
From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installed
http://www.ewido.net/en/download/updates/

==Download and save to desktop
FxNetsky.exe from Symantec's
Don't run it yet

==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup! 4.0
Give the link time to load or try it twice, it may be busy
Don't run this yet, we'll need it in a bit

Please Print this out or save these instructions to a Notepad file and save it to your Desktop

Access your Add/Remove programs and remove if found
Delphin media viewer
and Elitebar

RESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads, or use the link
I supplied for a more detailed explanation

In safe mode
==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
DECLINE to Log off or Restart

==Run FxNetsky.exe
Allow to finish scanning your drive and fix what it finds

====Open Ewido Security Suite
Click on the Scanner button on the left menu
Click on the Settings button on the right
Select "Scan Every File"
OK it and then click on the "Complete System Scan"
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  *1. Perform Action = Remove
  *2. Create Encrypted Backup in Quarantine (Recommended)
  *3. Perform action with all infections
  Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido

When Ewido is running do NOT open any other Windows
Let it do it's job

Restart back to Normal mode
Can I please see a few logs after you have done the above
Please post a fresh Hijackthis log
Also include the report from Ewidos
Let me know if FxNetsky fixed anything

Also
Download L2mfix from here

http://www.atribune.org/downloads/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

[color=\"red\"]IMPORTANT:  Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so![/color]
« Last Edit: August 08, 2005, 08:02:47 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline shawnpgorman

  • Newbie
  • *
  • Posts: 2
  • Karma: +0/-0
    • View Profile
pop-ups and memory error
« Reply #2 on: August 09, 2005, 03:09:59 AM »
here is the result:

Logfile of HijackThis v1.99.1
Scan saved at 4:04:49 AM, on 8/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\cusrvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\NALNTSRV.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\TIREMOTE\wuser32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\dpmw32.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\NWTRAY.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Cassetica\Cassetica NotesMedic Pro\NMPSystray.exe
C:\WINNT\system32\rundll32.exe
C:\Documents and Settings\beckerri\My Documents\programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://insite.nytco.com/
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NDPS] C:\WINNT\system32\dpmw32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NMPSystray.lnk = C:\Program Files\Cassetica\Cassetica NotesMedic Pro\NMPSystray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1123288439704
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1123288421458
O17 - HKLM\System\CCS\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{29400CCC-9887-4BBB-994A-4237B5B46818}: Domain = nytssc.om
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = shtmdc.com,nytssc.com,sscconnection.com,nytimes.com
O20 - Winlogon Notify: ShellCompatibility - C:\WINNT\system32\k408ledu1h08.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINNT\system32\NALNTSRV.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Track-It! Remote Control (TIRmtCtl) - Intuit Track-It! - C:\WINNT\TIREMOTE\wuser32.exe
O23 - Service: Track-It! Workstation Manager (TIRmtSvc) - Intuit, Inc. - C:\WINNT\TIREMOTE\TIRemoteService.exe

---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         3:02:27 AM, 8/9/2005
 + Report-Checksum:      DA77DA19

 + Scan result:

   HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\eZulaBootExe.EXE -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\eZulaMain.EXE -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\{8A044397-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\{C0335198-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE} -> Spyware.TopText : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\eZulaAgent.IEObject -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\eZulaAgent.IEObject\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\eZulaAgent.IEObject\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CLSID -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CurVer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{241667A3-EC83-4885-84DD-C2DAAFC1C5EA} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{25630B50-53C6-4E66-A945-9D7B6B2171FF} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{370F6353-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{788C6F6E-C2EA-4A63-9C38-CE7D8F43BCE4} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{78BCF936-45B0-40A7-9391-DCC03420DB35} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{955CBF48-4313-4B1F-872B-254B7822CCF2} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{9CFA26C2-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Classes\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51} -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer -> Spyware.eZula : Cleaned with backup
   HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
   HKLM\SOFTWARE\tsvcin -> Spyware.Look2Me : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\eZula -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\eZula\Setup -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\eZula\Setup\ID -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\eZula\Setup\path -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\Mvu -> Spyware.Delfin : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\Web Offer -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\Web Offer\Setup -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\Web Offer\Setup\ID -> Spyware.eZula : Cleaned with backup
   HKU\S-1-5-21-1768779481-1669139218-1539857752-3635\Software\Web Offer\Setup\Path -> Spyware.eZula : Cleaned with backup
   [552] C:\PROGRA~1\eZula\CHCON.dll -> Adware.eZula : Cleaned with backup
   [608] C:\PROGRA~1\WEBOFF~1\CHPON.dll -> Adware.eZula : Cleaned with backup
   [636] C:\PROGRA~1\ezula\seng.dll -> Adware.eZula : Cleaned with backup
   [772] C:\PROGRA~1\WEBOFF~1\wo.exe -> Adware.eZula : Cleaned with backup
   C:\Documents and Settings\beckerri\Local Settings\Temporary Internet Files\Content.IE5\8FM56RE3\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
   :mozilla.8:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.9:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
   :mozilla.10:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.11:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.12:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.13:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.14:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.15:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.16:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.17:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.18:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.19:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.20:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.21:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.22:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.35:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
   :mozilla.36:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
   :mozilla.45:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
   :mozilla.49:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.50:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.51:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.52:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.53:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.54:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
   :mozilla.55:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
   :mozilla.56:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
   :mozilla.57:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.61:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
   :mozilla.62:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
   :mozilla.65:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.71:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
   :mozilla.74:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.75:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.82:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
   :mozilla.83:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
   :mozilla.89:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
   :mozilla.90:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
   :mozilla.91:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
   :mozilla.92:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
   :mozilla.94:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
   :mozilla.95:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
   :mozilla.97:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
   :mozilla.98:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
   :mozilla.107:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.111:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
   :mozilla.114:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.115:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.116:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.125:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.126:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.127:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.128:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.129:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.130:C:\Documents and Settings\buettnm\Application Data\Mozilla\Firefox\Profiles\fg4tz2gm.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.15:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.16:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.17:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.18:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.19:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.20:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.21:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.22:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.23:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.24:C:\Documents and Settings\MONIXG\Application Data\Mozilla\Firefox\Profiles\1ixta7xp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.7:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
   :mozilla.22:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.23:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.24:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.25:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.26:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.27:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.28:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
   :mozilla.29:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
   :mozilla.31:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.45:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
   :mozilla.54:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
   :mozilla.55:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
   :mozilla.56:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
   :mozilla.57:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
   :mozilla.64:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.65:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.66:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.67:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.68:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.69:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
   :mozilla.70:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.71:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
   :mozilla.72:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.73:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.74:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   :mozilla.75:C:\Documents and Settings\woodc\Application Data\Mozilla\Firefox\Profiles\yeixcmh2.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
   C:\Program Files\AdDestroyer\AdDestroyer.exe -> Spyware.VirtualBouncer : Cleaned with backup
   C:\Program Files\eZula -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\basis.dst -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\basis.kwd -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\basis.pu -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\basis.rst -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\CHCON.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\eabh.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\GenLy.ez -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\genun.ez -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\arrow1.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\arrow2.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\button_small.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\corner_expand.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_LL.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_LR.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UL.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UL_2.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UL_NoFollow.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UR.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UR_2.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Corner_UR_NoFollow.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\icon.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Layer_Bottom.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Layer_Center.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Layer_Top.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\new.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Follow_divider.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Follow_Left.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Follow_Off.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Follow_On.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Follow_Right.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Top.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\PopUp_Top_Bottom.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Side_B.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Side_L.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Side_R.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\Side_Top.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\Images\spacer.gif -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\INSTALL.LOG -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\legend.lgn -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\mmod.exe -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\param.ez -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\rwds.rst -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\search.src -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\seng.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\ttupt.exe -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\UNWISE.EXE -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\upgrade.vrn -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\version.vrn -> Adware.eZula : Cleaned with backup
   C:\Program Files\eZula\wndbannn.src -> Adware.eZula : Cleaned with backup
   C:\Program Files\Microsoft AntiSpyware\Quarantine\B3615360-D0B5-48A9-BCC3-90E53C\2E5F85CF-7DA2-4966-AAD1-06FF40 -> Spyware.VirtualBouncer : Cleaned with backup
   C:\Program Files\Microsoft AntiSpyware\Quarantine\B3615360-D0B5-48A9-BCC3-90E53C\BA8F7B44-F750-4AC7-A460-0E242F -> Spyware.VirtualBouncer : Cleaned with backup
   C:\Program Files\Microsoft AntiSpyware\Quarantine\B3615360-D0B5-48A9-BCC3-90E53C\E349ED9A-901F-464C-8A7F-C4B6FD -> Spyware.VirtualBouncer : Cleaned with backup
   C:\Program Files\VBouncer\VirtualBouncer.exe -> Spyware.VirtualBouncer : Cleaned with backup
   C:\Program Files\Web Offer -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\apev.exe -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\basisp.dst -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\basisp.kwd -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\basisp.pu -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\basisp.rst -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\CHPON.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\eapbh.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\gendis.ez -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\INSTALL.LOG -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\paramp.ez -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\rwdsp.rst -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\sepng.dll -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\UNWISE.EXE -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\upgradep.vrn -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\versionp.vrn -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\wndbannnp.src -> Adware.eZula : Cleaned with backup
   C:\Program Files\Web Offer\wo.exe -> Adware.eZula : Cleaned with backup
   C:\WINNT\etb\nt_hide62.dll -> Spyware.EliteBar : Cleaned with backup
   C:\WINNT\etb\xud_62.dll -> Spyware.EliteBar : Cleaned with backup
   C:\WINNT\icont.exe -> Spyware.AdURL : Cleaned with backup
   C:\WINNT\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\avmparse.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\c000ladm1d0a.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\cjmsnap.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\dGd8.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\dn2s01f7e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\dn4601hse.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\e2202cfmgf2a2.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\enn2l15o1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\ezPopStub.exe -> Adware.eZula : Cleaned with backup
   C:\WINNT\system32\ezStub.exe -> Adware.eZula : Cleaned with backup
   C:\WINNT\system32\fIxmapi.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\fp0m03d1e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\fpru0399e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\g0040adqed0e0.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\g6jo0g13e6.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\gp80l3lm1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\gp86l3ls1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\gpp6l37s1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\gpr2l39o1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\h0l20a3oed.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\h60q0gd5e60.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\hfactivex.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\i2240cfqef2e0.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\i2nmlc511f.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\i8420ihoe84c0.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\iifgnt5.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\iTsnap.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\jt2207foe.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\jt4u07h9e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\jt6q07j5e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\jtju0719e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\k2080cduef080.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\kidbr.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\kt62l7jo1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\ktj0l71m1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\l20u0cd9ef0.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\lrncxw32.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\lvlq0935e.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\m682lglo16qc.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mbieftp.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mcls31.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mdvbvm60.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mdvidctl.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mhdxmlc.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mhnsspc.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\misip32.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mpacm32.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mrdimap.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mv22l9fo1.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\mv2ol9f31.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\n20050308.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
   C:\WINNT\system32\nqtcfgx.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\nv0029dmg.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\o4lule391h.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\o4pq0e75eh.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\p4r4le9q1h.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\p8n8li5u18.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\PopOops.dll -> Spyware.VirtualBouncer : Cleaned with backup
   C:\WINNT\system32\PopOops2.dll -> Spyware.VirtualBouncer : Cleaned with backup
   C:\WINNT\system32\pwapi.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\q8nu0i59e8.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\r0p8la7u1d.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\rrm.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\svardssp.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\SWLAD1.dll -> Spyware.VirtualBouncer : Cleaned with backup
   C:\WINNT\system32\SWLAD2.dll -> Spyware.VirtualBouncer : Cleaned with backup
   C:\WINNT\system32\t8r8li9u18.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\tDpi3.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\VJ5DB.DLL -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\vppxvdd.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\system32\wznhttp.dll -> Spyware.Look2Me : Cleaned with backup
   C:\WINNT\Temp\bw2.com -> Spyware.AdURL : Cleaned with backup


::Report End

-----------------------------------------------------------------------------
Symantec W32.Netsky FixTool 1.12.0


registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run: service (value deleted)

C:\System Volume Information: (not scanned)
C:\WINNT\system32\novell\nici\Admin.SHTUNISYS: (not scanned)
C:\WINNT\system32\novell\nici\oconnop.SHTUNISYS: (not scanned)
C:\WINNT\system32\novell\nici\SYSTEM: (not scanned)
D:\System Volume Information: (not scanned)
W32.Netsky has not been found on your computer.

still getting pop-up while browsing internet like a search helper object.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
pop-ups and memory error
« Reply #3 on: August 09, 2005, 08:31:45 AM »
Just on my way to work, I'll still need to see the log after you run L2MFix
Link and directions are im my first reply

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


scorpy

  • Guest
pop-ups and memory error
« Reply #4 on: September 11, 2005, 01:40:10 PM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> install and run cccleaner. I had the same issue for long time and this removed the problem.
all the best