Alright, here u go this is the log file from l2mfix:
L2mfix 010406
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Running From:
C:\WINDOWS\system32
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 480 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 552 'winlogon.exe'
Killing PID 552 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 228 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1504 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
Second pass Completed!
1 file(s) copied.
1 file(s) copied.
1 file(s) copied.
Deleting: C:\WINDOWS\system32\k8jsli1718.dll
Successfully Deleted: C:\WINDOWS\system32\k8jsli1718.dll
Deleting: C:\WINDOWS\system32\kt2ul7f91.dll
Successfully Deleted: C:\WINDOWS\system32\kt2ul7f91.dll
Deleting: C:\WINDOWS\system32\nnlsapi.dll
Successfully Deleted: C:\WINDOWS\system32\nnlsapi.dll
msg11?.dll
0 file(s) copied.
Restoring Windows Update Certificates.:
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Shell Extensions]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\kt2ul7f91.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbjt32]
"Asynchronous"=dword:00000001
"DllName"="winbjt32.dll"
"Impersonate"=dword:00000000
"Startup"="EvtStartup"
"Shutdown"="EvtShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
The following are the files found:
****************************************************************************
C:\WINDOWS\system32\k8jsli1718.dll
C:\WINDOWS\system32\kt2ul7f91.dll
C:\WINDOWS\system32\nnlsapi.dll
Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}\InprocServer32]
@="C:\\WINDOWS\\system32\\SvnthCore11Resources.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{72B9F897-78E6-4930-B4FE-80E3091794E6}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{72B9F897-78E6-4930-B4FE-80E3091794E6}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{72B9F897-78E6-4930-B4FE-80E3091794E6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{72B9F897-78E6-4930-B4FE-80E3091794E6}\InprocServer32]
@="C:\\WINDOWS\\system32\\mgiwave.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}\InprocServer32]
@="C:\\WINDOWS\\system32\\nnlsapi.dll"
"ThreadingModel"="Apartment"
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}"=-
"{72B9F897-78E6-4930-B4FE-80E3091794E6}"=-
"{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}"=-
[-HKEY_CLASSES_ROOT\CLSID\{A2FB58C9-164D-4FB6-88C1-300F01D6BBBD}]
[-HKEY_CLASSES_ROOT\CLSID\{72B9F897-78E6-4930-B4FE-80E3091794E6}]
[-HKEY_CLASSES_ROOT\CLSID\{71B9C6FF-B129-4672-8EC0-5A30B3917BCD}]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/k8jsli1718.dll (164 bytes security) (deflated 4%)
adding: dlls/kt2ul7f91.dll (164 bytes security) (deflated 5%)
adding: dlls/nnlsapi.dll (164 bytes security) (deflated 5%)
adding: backregs/71B9C6FF-B129-4672-8EC0-5A30B3917BCD.reg (212 bytes security) (deflated 70%)
adding: backregs/72B9F897-78E6-4930-B4FE-80E3091794E6.reg (212 bytes security) (deflated 70%)
adding: backregs/A2FB58C9-164D-4FB6-88C1-300F01D6BBBD.reg (212 bytes security) (deflated 70%)
adding: backregs/notibac.reg (164 bytes security) (deflated 77%)
adding: backregs/shell.reg (164 bytes security) (deflated 74%)
Log file from hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 10:12:31 AM, on 01/03/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 15\minimavis.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://go.compaq.com/1Q00CDT/0409/bl8.aspR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [win msdt service] mswindtc.exe
O4 - HKCU\..\RunServices: [win msdt service] mswindtc.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Personal Coach.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.companion....ebio5_1_6_0.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Teachers-Desk
O17 - HKLM\Software\..\Telephony: DomainName = Teachers-Desk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Teachers-Desk
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\kt2ul7f91.dll (file missing)
O20 - Winlogon Notify: winbjt32 - winbjt32.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Log file from Ewido:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 6:38:16 PM, 28/02/2006
+ Report-Checksum: F89593E0
+ Scan result:
[632] C:\WINDOWS\system32\mrpmsp.dll -> Adware.Look2Me : Error during cleaning
[712] C:\WINDOWS\system32\mrpmsp.dll -> Adware.Look2Me : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831170103.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831170103.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831170103.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831170103.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831174456.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831174456.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831174456.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831174456.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831180146.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831180146.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831180146.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831184122.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831184122.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831184122.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050831184122.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113529.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113940.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113940.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113940.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901113940.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901114156.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050901114156.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050902124503.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050902124503.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050902124503.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050902124503.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050902124503.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903101552.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903101552.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903101552.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903101552.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903101552.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903153214.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903153214.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903153214.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903153214.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050903153214.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050904110943.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050904110943.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050904110943.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050904110943.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050904110943.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050905084536.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050905084536.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050905084536.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050905084536.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050905084536.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050906084155.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050906084155.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050906084155.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050906084155.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050906084155.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050907085345.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050907085345.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050907085345.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050907085345.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050907085345.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050908084509.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050909090322.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050910124907.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050913094059.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050914103700.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050915105857.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050916114543.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050917101413.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050918111612.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050920094702.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsS.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsB.dll -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsA.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WSup.exe -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsB.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsS.to_be_deleted -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050921102730.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20060126184236.zip/Program Files/common files/wintools/WToolsB.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20060126184236.zip/Program Files/common files/wintools/WToolsS.to_be_deleted_x -> Adware.Wintol : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq10D.tmp\sfbho.dll -> Adware.SideFind : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\common.dll -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\nzqlihv.wzg -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\PIB.exe -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\TBPS.exe -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\TBPSSvc.exe -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp\toolbar.dll -> Adware.WebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq43.tmp -> Adware.BargainBuddy : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq44.tmp -> Adware.BargainBuddy : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq45.tmp -> Adware.BargainBuddy : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5C.tmp\bin\nls.exe -> Adware.BargainBuddy : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq64.tmp\sais.exe -> Adware.180Solutions : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA.tmp -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD.tmp -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp -> TrackingCookie.Adserver : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ysbactivex.dll -> Downloader.IstBar : Cleaned with backup
C:\WINDOWS\gimmygames.exe -> Downloader.VB.vr : Cleaned with backup
C:\WINDOWS\gimmygames9.exe -> Downloader.VB.ww : Cleaned with backup
C:\WINDOWS\system32\AdService.dll -> Trojan.Agent.og : Cleaned with backup
C:\WINDOWS\system32\en0ml1d11.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\g0040adqed0e0.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i6jq0g15e6.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ir2sl5f71.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ir4ml5h11.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ir8sl5l71.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\irp6l57s1.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k6lqlg3516.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k8no0i53e8.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ktj6l71s1.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ktlul7391.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kzdest.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l06o0aj3edo.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\m6po0g73e6.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mvl4l93q1.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\n08o0al3edq.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\SvnthCore11Resources.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sxsvc.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wahisn.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\winbjt32.dll -> Trojan.Agent.og : Cleaned with backup
C:\WINDOWS\Temp\~483948.tmp -> Adware.Wintol : Error during cleaning
C:\WINDOWS\Temp\~540970.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~585342.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~615033.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~707015.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~779169.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~783512.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~785394.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~869831.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\Temp\~873933.tmp -> Adware.Wintol : Error during cleaning
C:\WINDOWS\Temp\~878524.tmp -> Downloader.Wintool.a : Error during cleaning
C:\WINDOWS\winsysban10.exe -> Hijacker.VB.ld : Cleaned with backup
C:\WINDOWS\winsysban3.exe -> Hijacker.VB.kc : Cleaned with backup
C:\WINDOWS\winsysban8.exe -> Hijacker.VB.lg : Cleaned with backup
C:\WINDOWS\winsysban9.exe -> Hijacker.VB.ld : Cleaned with backup
C:\WINDOWS\winsysupd10.exe -> Downloader.VB.wg : Cleaned with backup
C:\WINDOWS\winsysupd4.exe -> Hijacker.StartPage.ahg : Cleaned with backup
C:\WINDOWS\winsysupd5.exe -> Hijacker.StartPage.ahg : Cleaned with backup
C:\WINDOWS\winsysupd6.exe -> Downloader.VB.wg : Cleaned with backup
C:\WINDOWS\winsysupd7.exe -> Downloader.VB.wg : Cleaned with backup
C:\WINDOWS\winsysupd8.exe -> Hijacker.StartPage.ahg : Cleaned with backup
C:\WINDOWS\winsysupd9.exe -> Downloader.VB.wy : Cleaned with backup
C:\winsysban5.exe -> Hijacker.VB.kc : Cleaned with backup
::Report End