Author Topic: Kyoukan hijackthis log  (Read 1361 times)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Kyoukan hijackthis log
« on: September 12, 2005, 06:58:31 PM »
Posting this here for you Kyoukan
Better if we start a new post instead of posting in anothers  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Here is my Hijack THis Report. I'll wait until you have taken a look at it before I do anything. I have most(if not all) the programs you mentioned in the above post.  

Logfile of HijackThis v1.99.1
Scan saved at 4:26:48 PM, on 9/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
F:\programes\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Programes\NortonSystemWorks\Norton Utilities\NPROTECT.EXE
F:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
F:\PROGRA~1\VEXIRA~1\Bin\vbcmserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
F:\PROGRA~1\VEXIRA~1\Bin\vbsystry.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\ctfmon.exe
F:\programes\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\PerSono\perstray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Foxmail\Foxmail.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
F:\Programes\Firefox\firefox.exe
G:\Valve\Steam\Steam.exe
g:\valve\steam\steamapps\matttheassassin\sourcesdk\bin\hammer.exe
C:\Program Files\Foxmail\FoxHot.exe
H:\AntiVirusandSpyware\hijackthis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [VBSysTray] "F:\PROGRA~1\VEXIRA~1\Bin\vbsystry.exe"
O4 - HKLM\..\Run: [AVLoginToDo] "F:\PROGRA~1\VEXIRA~1\Bin\avltd.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\programes\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Perstray.lnk = ?
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O10 - Unknown file in Winsock LSP: f:\progra~1\vexira~1\bin\vblsp.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6EE39BFC-2FB6-4B69-9D05-CFC10E4F5B3E} (MavenBootInstallerAXControl Class) - http://client.maven.net/client/mavenBootInstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95732E8F-9538-4137-9B73-6282DE81ED7B}: Domain = evansville.net
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - F:\programes\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\Programes\NortonSystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Vexira Antivirus Component Manager Service (VACompManService) - Central Command, Inc. - F:\PROGRA~1\VEXIRA~1\Bin\vbcmserv.exe


I have the infected  files quarentined with Ad-Aware SE

WIN32.P2P-WORM.ALCAN.A
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=File : C:\WINDOWS\system32\bszip.dll
obj[1]=Regkey : software\microsoft\downloadmanager
obj[2]=File : C:\WINDOWS\System32\cmd.com
obj[3]=File : C:\WINDOWS\System32\netstat.com
obj[4]=File : C:\WINDOWS\System32\ping.com
obj[5]=File : C:\WINDOWS\System32\regedit.com
obj[6]=File : C:\WINDOWS\System32\taskkill.com
obj[7]=File : C:\WINDOWS\System32\tasklist.com
obj[8]=File : C:\WINDOWS\System32\tracert.com
« Last Edit: September 12, 2005, 06:59:36 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Kyoukan hijackthis log
« Reply #1 on: September 12, 2005, 07:14:08 PM »
It's nice to see Ad-Aware is removing the bad files now, that's a bonus

Can you do the following for me please
From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link
http://www.ewido.net/en/download/updates/

Also open Ad-Aware and check for updates
Run this later

I know you have the tools, so let's make sure we run them just in case
If you didn't intentionally install ViewPoint
Access your add/remove programs and remove reference to it
You may have more than one entry listed

Run Pocket KillBox.exe

In the killbox program, select the Delete on Reboot option.
Copy the file names below to the clipboard by highlighting them and pressing
Control + C

Killbox files to highlight between dotted lines
===================================================
C:\Program Files\MsConfigs\MsConfigs.exe
C:\WINDOWS\system32\p2pnetwork.exe
C:\WINDOWS\system32\CMD.COM
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tracert.com
C:\Program Files\winupdate\winupdate.exe


===================================================
*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer doesn't restart
Please Restart it now manually into SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads, or use the link
I supplied for a more detailed explanation

In safe mode

Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Find and delete this folder
C:\Program Files\winupdates <-this folder

==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
DECLINE to Log off or Restart when scan is done.

==Open Ewido trojan scanner
Click on the Scanner button on the left menu
Click on the Settings button on the right
Select "Scan Every File"
OK it and then click on the "Complete System Scan"
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  *1. Perform Action = Remove
  *2. Create Encrypted Backup in Quarantine (Recommended)
  *3. Perform action with all infections
  Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido

NOTE: When Ewido is running do NOT open any other Windows
Let it do it's job

Do another scan with Hijackthis and put a check next to these entries:

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto

You can have hijackthis fix the next ones
Registration reminders for products installed, not needed on startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe


If you removed Viewpoint from the add/remove programs, please tick the next ones too
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll


After you have ticked the above entries, close All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Open Ad-Aware
Click START
Click the radio button to Perform a Full system scan then click NEXT
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button

Restart back to Normal mode

Please post a fresh Hijackthis log and the report from Ewidos

Note: You have Spybot's Tea Timer running, it's a great tool
But if prompted by tea timer about changes
ALLOW them so it won't interfere with any fixes we are doing

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Kyoukan

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Kyoukan hijackthis log
« Reply #2 on: September 13, 2005, 11:27:17 PM »
Just in case you didn't get my message, I am not sure when I can start the removal of this worm. I won't know from day to day if I can start the ball rolling until after work.  If I don't get around to it durring the week I will definitly do it this weekend. I am posting this to let you know that I am not ignoring you and am very commited to remove this worm. I'll be out with the reports as soon as  I can.

Offline Kyoukan

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Kyoukan hijackthis log
« Reply #3 on: September 26, 2005, 10:05:14 PM »
ok here is the two reports. I didn't elmintate winupdate because one the folder was empty and two a different worm was cleaned off of it before.

---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         6:41:26 PM, 9/26/2005
 + Report-Checksum:      2C6D0844

 + Scan result:

   HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
   :mozilla.23:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.31:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.32:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.33:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.34:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.38:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.39:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
   :mozilla.40:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
   :mozilla.41:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
   :mozilla.42:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
   :mozilla.46:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
   :mozilla.52:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.53:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.54:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.55:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.58:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.60:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.63:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.83:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.86:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.87:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.89:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.90:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.91:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.92:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.93:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.94:C:\Documents and Settings\Matthew Doucet\Application Data\Mozilla\Firefox\Profiles\k7tfa35m.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\1Click DVD Copy 4.2.1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\1Click DVD Copy v4.2.1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\1st Choice Ftppro 8.54182.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\2 Beautiful Lesbians.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\24Fun Drawing Animator.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AAVoice v1.4.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Absolute Video Converter 2.5.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ABviewer 5.0.1.47.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Acronis Disk Director Suite 9.0.533.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Active Download Accelerator 5.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Advanced MP3 Sound Recorder v1.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Agnitum Outpost Firewall Pro 27493.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Ahead DVD Ripper 1.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Ahead Nero InCD 4.3.14.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Alcohol 120% 1.9.5.3105.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Alcohol 120%.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Alias Maya Unlimited v7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\All-In-One Dachshund Products.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Amadis DVD Ripper Pro 1.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Amazing Slow Downer 2.72.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Amazon DVD Shrinker 2.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AmeRiCan PiE 1 - 2 and 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AnyDVD 5.4.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AnyDVD v5.4.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Apollo DVD Copy 4.5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Audio Formats SDK 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Autorun Pro 6.0.0.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AutoUpdate Plus 3.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\AutoUpdate Plus v3.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Batch Video Converter v1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Batch Video Joiner v1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Batman Begins.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Big Tit [censored].zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Billingtracker Pro 3.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Blaze DVD Copy 3.5.9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\BloodRayne 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Boilsoft AVI MPEG ASF WMV Splitter v3.24.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Butterfly Effect ( 2004 ).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Capture WebCam 2.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Capture WebCam v2.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Carmen Electra- Playboy DVD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Catalog Max V1.66.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CCleaner v1.22.142.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Cheetah DVD Burner 1.45.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CliMail v1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CloneCD 5.2.6.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CloneDVD v3.6.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ColorShade 2.5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Cool CD Burner 2.22.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Crystal Player Pro 1.96.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CuteHTML Pro v6.057.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\CyberArticle v4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Delphi 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Deluxeware.EarthNavigator.Pro.v1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Digital Photo Resizer v2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\DirSize 4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\DirSize v4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\DmxZone Flash Album Generator 1.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Dungeon Siege 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\DVDFab Platinum 2.9.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\EarthView v3.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy Audio Converter Professional 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy DVD CD Burner 3.0.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy DVD CD Burner v3.0.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy DVD Shrink 3.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy DVD Shrink v3.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy File Sharing Web Server 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy File Sharing Web Server v3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Easy.ScreenSaver.Maker.v2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\egistry Mechanic 5.0.0.135.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Elby CloneDVD 2.8.5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Error Doctor 2006 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ETU Wasser Plus 1.006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\FaceGen Modeller 3.12 full.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Fantastic Four Xvid.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Farstone VirtualDrive 9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\File ArchiveRescue Pro 2.6.63.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Final fantasy 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Flash4d 3.0 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\FlashFXP v3.3.0 Build 1087 Beta.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\FotoAlbum Professional v4.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Free Internet Tv 4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Full Screen Player 0.4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Futurama - S05E06 - Less than hero.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Game XP 1.5.2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Harry Potter 4 And The Goblet Of Fire.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Headsoft Clone Cleaner Pro 1.02.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Hide Ip Platinum 1.61.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Hide IP Platinum 1.62.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Hide IP v1.82.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Hustle & Flow.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Hustle &amp; Flow.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Im Juli.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Inbit FullShot Enterprise 8.5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Internet Download Manager v4.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\IntroCreator v2.00.020031.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ISO Commander 1.6.031 RC2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Jay and Silent Bob Strike Back (2001).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Kaspersky Antivirus Pers v5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Kingdia DVD Ripper Pro 2.4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Krystal First Time [censored].zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Limewire Acceleration Patch 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\LimeWire PRO (Latest).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Little Fighter 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Lord of the rings 1-2 and 3 (ftp).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\LUXONIX.Ravity.16.VST.v1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\LUXONIX.Ravity.R.VSTi.v1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Macro Recorder 1.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Macromedia Fontographer 4.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Media Detective 2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Micro Sys TimeSage 1.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Microsoft Office 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\MindFusion.FlowChart.NET.Pro.v3.2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Motamo.v1.0.WinALL.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Movie Writer Pro v2.70.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\MP3Bee.CD.Burning.Tool.v3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\MP3Doctor 5.11.026.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\MP3Producer 2.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Need For Speed Underground 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Nero Burning ROM 6.6.0.16.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\NewLive.All.Media.To.Mp3.Converter.Pro.v.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\NewLive.AVI.To.VCD.SVCD.DVD.MPEG.Convert.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\NewLive.RM.To.AVI.VCD.SVCD.DVD.MPEG.Conv.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\NewLive.Wmv.to.Avi.Divx.VCD.DVD.Converte.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\No1 DVD Audio Ripper 1.0.44.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\No1 Video Converter 3.8.12.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Ocean FTP Server 1.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Office DocumentsRescue Pro 2.6.71.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\One Click Cd Converter v1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Opera 7.54 Update 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Paris Hilton Sex Tape.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Partition Magic 8 Professiona.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\PhotoDVD 2.09.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Photoplorer v1.17.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Plato DVD Ripper 1.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Popup Ad Stopper 9.80.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\PowerArchiver 9.20.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\PrivateFirewall 4.0.18.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Quick CD Ripper v2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Radar Website Monitor 4.5.7.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Real Spy Monitor V2.36.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ReGet Deluxe 4.1a Build 247.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Robo-FTP 2.1.2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Savage The Battle for Newerth.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Sex 13 min Japanese girl.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Showme 1.9.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\SmartFTP 1.5.988.50.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Sophos Anti-Virus 3.90.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\South Park 709 - Christian Hard Rock.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Speed Video Splitter 2.1.9.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\SpeedUpMyPC 2.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Spy Emergency 2005 2.0.300.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Spyware Doctor v3.2.1.359.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\StarCraft & Starcraft Brood War (ISO).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\TextPad 4.7.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\The Island 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\The Longest Yard (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Tinynice MP3Cutter 2.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Trojan Remover 6.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\TuneUp Utilities 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\ViceVersa Pro 2.0.0.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Video Vault 3.0156.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Virtual CD v7.1.0.0 Network Edition.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Virtual Desktop Toolbox 2.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Visual CertExam Suite v1.7.542.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Warez P2P 2.85 .zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Webroot Spy Sweeper 3.5.0.194.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Wedding Crashers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinBackup v2.0.8 Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Windows XP Pro SP2 Corporate.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinGet 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinGet v2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinOKE 3.20 - karaoke.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinPatrol v9.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinTasks Pro 5.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WinXP Manager 4.92.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WorldWide FTP 2.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\WWAYM.NWMaxx.VST.v1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Xeru Image Converter 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\XP Codec Pack 1.2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\XP Codec Pack v1.2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Zealot All Video Joiner v1.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Documents and Settings\Matthew Doucet\Complete\Zealot All Video Splitter v1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
   C:\Program Files\winupdates\a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
   :mozilla.9:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.14:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.36:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.37:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.61:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.62:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.63:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.67:C:\RECYCLER\NPROTECT\00002848.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.9:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.12:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.13:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.31:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.32:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.38:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.39:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.40:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.41:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.42:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.55:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002849.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.9:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.12:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.13:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.31:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.32:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.38:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.39:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.40:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.41:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.42:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.55:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002851.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.11:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.14:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.33:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.34:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.40:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.41:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.42:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.55:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.61:C:\RECYCLER\NPROTECT\00002852.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.10:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.37:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002853.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.8:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.37:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002854.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.10:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.37:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002855.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.10:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.37:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002856.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.10:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.11:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.16:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.20:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.43:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.44:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.45:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.46:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.56:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002857.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.15:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.16:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.20:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.23:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.24:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.61:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.62:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.63:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.68:C:\RECYCLER\NPROTECT\00002916.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.17:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.20:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.23:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.24:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.47:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.57:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.60:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.61:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.62:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.63:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.68:C:\RECYCLER\NPROTECT\00002918.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.21:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.24:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.25:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.50:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.51:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.52:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.53:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.54:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.55:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
   :mozilla.58:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.59:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
   :mozilla.61:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.62:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.63:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.64:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.65:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
   :mozilla.69:C:\RECYCLER\NPROTECT\00002919.MOZ -> Spyware.Cookie.Bluestreak : Cleaned with backup
   :mozilla.18:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
   :mozilla.19:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
   :mozilla.21:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.24:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.25:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
   :mozilla.48:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
   :mozilla.49:C:\RECYCLER\NPROTECT\00002920.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
   :mozilla.5

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Kyoukan hijackthis log
« Reply #4 on: September 27, 2005, 08:44:08 PM »
You never posted a fresh Hijackthis log or the whole Ewido report???

I suggest that you delete the following folder

 C:\Documents and Settings\Matthew Doucet\Complete <--the Complete folder

Afterwards
Check for updates with Ewido and run another scan
When the scan is done, save the new report and post the whole thing

Also post a fresh log from Hijackthis

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here