Author Topic: Please help me fix this computer  (Read 360 times)

Offline darko2021

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
Please help me fix this computer
« on: June 07, 2006, 10:53:04 AM »
I am trying to fix my mothers comp. and I think it's just craped out (I think system elements might have been deleted/corrupted some how as she is plagued with instability messages) and I am going to have to reinstall her OS.
If someone could please give me step by step instructions on how exactly I can do this it would be awesome.
Here is her hijack this any way just in case the cpu is savable. Thank you in advance for any help.

Logfile of HijackThis v1.99.1
Scan saved at 11:44:00 AM, on 6/7/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://freehqmovies.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/5/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINDOWS\system32\searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/1/search.php?qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\info32.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1423.0\en-us\msntb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 64.127.104.144 (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potb_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://hard-virgins.com/dl/dmitriy/x.chm::/load.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...73/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136780544265
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127269678831
O16 - DPF: {8B6193F1-837F-11D4-89E6-0050DA666184} (Sol2axctl Class) - http://download.solitaire.com/download/solitaire.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...666/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{88610269-D0FC-4BF3-B7B3-9250A83A8925}: NameServer = 209.244.0.3 209.244.0.4
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)
O19 - User stylesheet: C:\WINDOWS\Web\win.def (file missing)
O19 - User stylesheet: C:\WINDOWS\default.css (file missing) (HKLM)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: System - {06182965-B671-44A9-BA14-1892F4A16091} - C:\WINDOWS\system32\system32.dll (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Workstation NetLogon Service (O?’ŽrtñåȲ$Ó) - Unknown owner - C:\WINDOWS\d3ut.exe (file missing)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please help me fix this computer
« Reply #1 on: June 07, 2006, 11:45:09 AM »
Can you do the following please

We should be able to clean the computer without reinstall
Can you open Hijackthis>>Open Misc tools section>>Open Uninstall manager
Click the SAVE LIST button
Save this list too your desktop, then copy and paste back here the whole contents please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline darko2021

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
Please help me fix this computer
« Reply #2 on: June 07, 2006, 01:09:18 PM »
Here it is and thank you for helping me.


ABBYY FineReader 5.0 Sprint
ACDSee 4.0 PowerPack Suite
Ad-aware Plus 5.83
Adobe Acrobat 5.0
Adobe Photoshop 7.0
AOL Instant Messenger
Application Verifier Database
BCM V.92 56K Modem
CleanUp!
CleverKeys
Color Schemer 2.5
Compatibility Administrator 3.0
CuteFTP Pro
Dell AIO Printer A940
Dell Modem-On-Hold
Dell ResourceCD
Dell Support 5.0.0 (766)
Digital Line Detect
Direct Connect 1.0 Preview Build 9
DivX 5.0.1 Bundle
EPSON Printer Software
FaxTools
Focus On Fundamentals
Half-Life
HijackThis 1.99.1
Home  Search Assistent
hp instant support
HP Memories Disc
HP Photo and Imaging 2.0 - Photosmart Cameras
hp printer cover software
Intel® Extreme Graphics Driver
IsoBuster 1.4
Macromedia Flash MX
McAfee SecurityCenter
McAfee VirusScan
McAfee.com Privacy Service
Microsoft Application Compatibility Analyzer 1.0
Microsoft Office 2000 Professional
MSN
MSN Dial Up Accelerator
MSN Messenger 6.0
MSN Toolbar
Natural Selection
Nero - Burning Rom (Web installer)
P2P Networking
Peer Points Manager
Piolet 1.05
Popup Ad Filter Release 1
Quicken 2001 Home & Business
QuickTime
RealPlayer Basic
Refupdate 2.0
SafeCast Shared Components
Search  Extender  
Shopping Wizard  
Sierra Utilities
Submit URL
TurboTax Basic 2002
TurboTax Basic 2003
TurboTax Deluxe 2004
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
waypt_pakv13.5
WebCyberCoach 3.2 Dell
WexTech AnswerWorks
Winamp (remove only)
Windows Application Verifier 2.50
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB824146
Windows XP Hotfix (SP2) Q811493
WinMX
WinRAR archiver
Yahoo! Toolbar for Internet Explorer

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please help me fix this computer
« Reply #3 on: June 07, 2006, 02:44:52 PM »
Can you do the following please

==Download CWShredder.exe and save to your desktop, don't run yet

Download AboutBuster.zip  and unzip the files to a folder on your Desktop
We'll need this later

==Download and then Install
Ewido anti-malware 3.5

When installing, under "Additional Options" Uncheck
 "Install background guard" and "Install scan via context menu".

From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installed
http://www.ewido.net/en/download/updates/

Your version of Ad-Aware is terribly out of date
Can you access your add/remove programs and remove
Ad-aware Plus 5.83
and
Refupdate 2.0


Afterwards
Download and Install
Ad-Aware SE Personal 1.06

Open Ad-Aware, ensure to click the  check for updates now link and Connect to download the latest updates
Close out after it is updated, as we will need it later
Don't run a scan yet, we'll need it later

Save the rest of these instructions to a Notepad file saved to your desktop or Print them out for use in safe mode

RESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Choose Safe mode from the startup menu

Go to START>>>RUN>>>type in services.msc
Hit OK
In the next window, look on the right hand side for this Exact service
name---- Workstation NetLogon Service

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Disabled

Again, access your add/remove programs via control panel
Remove the following if you can, if not remain in safe mode and carry on with the instructions regardless
Home Search Assistent
P2P Networking
Peer Points Manager
Search Extender
Shopping Wizard
Submit URL
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)


Remain in safe mode, even if prompted to reboot
Run Cwshredder.exe
Click on the FIX button,(Make sure to run the FIX and not the Scan, the scan won't do nothing)
 let it run and fix whatever it finds
When it's done
Exit
Don't reboot yet

Double click to run AboutBuster and click Begin Removal button. Once that's scan is done, Hit OK Click Exit once you are done. Click the OK button and it should exit.

Remain in safe mode
==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):

* Empty Recycle Bins
* Delete Cookies
* Delete Prefetch files
* Cleanup! All Users

Click OK
Press the CleanUp! button to start the program.
When it's done, decline to log off or restart the computer

==Open Ewido Anti-Malware
Click on the Scanner button on the left menu
Select Complete System Scan
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  *1. Perform Action = Remove
  *2. Create Encrypted Backup in Quarantine (Recommended)
  *3. Perform action with all infections
  Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop or a folder you will remember later
Exit Ewido
NOTE: As Ewido is running, let it finish uninterrupted, don't open any other windows

Remain in safe mode
Do a "System scan only" with Hijackthis and put a check next to these entries:

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://freehqmovies.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/5/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vmpyj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINDOWS\system32\searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/1/search.php?qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\info32.exe
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 64.127.104.144 (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://hard-virgins.com/dl/dmitriy/x.chm::/load.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)
O19 - User stylesheet: C:\WINDOWS\Web\win.def (file missing)
O19 - User stylesheet: C:\WINDOWS\default.css (file missing) (HKLM)

O21 - SSODL: System - {06182965-B671-44A9-BA14-1892F4A16091} - C:\WINDOWS\system32\system32.dll (file missing)
O23 - Service: Workstation NetLogon Service (O?’ŽrtñåȲ$Ó) - Unknown owner - C:\WINDOWS\d3ut.exe (file missing)


After you have ticked the above entry, close All other open windows
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Open Ad-Aware SE 1.06
Click START
Click the radio button to Perform a Full system scan then click NEXT
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button


Reboot back to Normal mode
Access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the General tab--- Reset home page

1. Post back a fresh hijackthis log
2. Post the Whole report from Ewidos' you saved earlier
3. AboutBuster would of created a log called 'Ab LogFile.txt'
Can you post it too please
« Last Edit: June 07, 2006, 05:59:41 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline darko2021

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
Please help me fix this computer
« Reply #4 on: June 07, 2006, 07:48:47 PM »
Ok so here are the new reports, some of the hijackthis files you told me to check didn't show up. any way
thank you sooo much for your help. Hope every things ok.

Logfile of HijackThis v1.99.1
Scan saved at 8:41:09 PM, on 6/7/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1423.0\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potb_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc...73/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136780544265
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127269678831
O16 - DPF: {8B6193F1-837F-11D4-89E6-0050DA666184} (Sol2axctl Class) - http://download.solitaire.com/download/solitaire.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...666/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe


AboutBuster 6.01
Scan started on [6/7/2006] at [6:45:42 PM]
-------------------------------------------------------------
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
-------------------------------------------------------------
Removed Stream! C:\WINDOWS\msnavpklog.txt:ldnoy
Removed Stream! C:\WINDOWS\nsw.log:gfreo
Removed Stream! C:\WINDOWS\orun32.isu:yupks
Removed Stream! C:\WINDOWS\PowerReg.dat:jvhxu
Removed Stream! C:\WINDOWS\Q811493.log:bvsdo
Removed Stream! C:\WINDOWS\wfiqy.dat:oqhza
Removed Stream! C:\WINDOWS\WIASERVC.LOG:hraeu
Removed Stream! C:\WINDOWS\Windows Update.log:zkkkw
-------------------------------------------------------------
Removed File! : C:\WINDOWS\cyndp.txt
Removed File! : C:\WINDOWS\dtbwc.log
Removed File! : C:\WINDOWS\hdgwj.log
Removed File! : C:\WINDOWS\hrvov.dat
Removed File! : C:\WINDOWS\lazhb.dat
Removed File! : C:\WINDOWS\naihd.dat
Removed File! : C:\WINDOWS\ospgv.txt
Removed File! : C:\WINDOWS\poxbm.dat
Removed File! : C:\WINDOWS\qigiq.txt
Removed File! : C:\WINDOWS\ruqqx.dat
Removed File! : C:\WINDOWS\uipcg.dat
Removed File! : C:\WINDOWS\vpfkf.dat
Removed File! : C:\WINDOWS\wfiqy.dat
Removed File! : C:\WINDOWS\wxcop.dat
Removed File! : C:\WINDOWS\System32\ajbfh.dat
Removed File! : C:\WINDOWS\System32\bveve.dat
Removed File! : C:\WINDOWS\System32\ijrnk.dat
Removed File! : C:\WINDOWS\System32\jbuip.dat
Removed File! : C:\WINDOWS\System32\lahbu.txt
Removed File! : C:\WINDOWS\System32\lcizy.dat
Removed File! : C:\WINDOWS\System32\qdjcn.dat
Removed File! : C:\WINDOWS\System32\rfyxr.dat
Removed File! : C:\WINDOWS\System32\rglhy.log
Removed File! : C:\WINDOWS\System32\rtljy.dat
Removed File! : C:\WINDOWS\System32\spadc.log
Removed File! : C:\WINDOWS\System32\tsjhn.txt
Removed File! : C:\WINDOWS\System32\tthti.dat
Removed File! : C:\WINDOWS\System32\uiuje.dat
Removed File! : C:\WINDOWS\System32\xtuqo.dat
Removed File! : C:\WINDOWS\System32\ycduf.dat
Removed File! : C:\WINDOWS\System32\ygbkw.dat
-------------------------------------------------------------
Removed Temp Files
Internet Explorer Settings Reset!
-------------------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 6:49:25 PM




---------------------------------------------------------
 ewido anti-malware - Scan report
---------------------------------------------------------

 + Created on:         7:52:32 PM, 6/7/2006
 + Report-Checksum:      88E27238

 + Scan result:

   HKLM\SOFTWARE\Altnet -> Adware.Altnet : Error during cleaning
   HKLM\SOFTWARE\Altnet\ADM -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\Dashboard -> Adware.Altnet : Error during cleaning
   HKLM\SOFTWARE\Altnet\Dashboard\Messages -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Adware.Altnet : Error during cleaning
   HKLM\SOFTWARE\Altnet\Dashboard\Setup -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\Dashboard\Temp Internet Shares -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\DownloadManager -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\LocalFiles -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Altnet\TopSearch -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM.ADM -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM.ADM\CLSID -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM.ADM\CurVer -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM.ADM.1 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM25.ADM25.1 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ADM4.ADM4.1 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\ae23.ae23Obj -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\ae23.ae23Obj\CLSID -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\ae23.ae23Obj\CurVer -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\ae23.ae23Obj.1 -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{13F515CF-0C52-2DB2-DD18-6D86CD3486CB} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{15FEC491-F0D8-A206-B818-8D1D3FEDF979} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{188BBE09-BA8D-5A3C-D78E-440A0EE5FF3E} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{201C2FBF-3759-3A0D-344E-15772DA97FF5} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{21258EF1-13DE-0334-9DB4-2B3E344FFB37} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{22A97394-EB34-0653-AF9D-BCB8831CBDCC} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{24B03FDF-5DE1-270C-11C7-3A22B612A1ED} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{265118BC-05C6-4CB4-EBB4-7407CDEF02FE} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{27244056-A7A0-0D52-E7EF-5AC1509FDFAA} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{27B7B1C6-9CB4-0DCD-50C3-E8A0B4BD572C} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{35E5DE50-A6E0-38C5-C988-2FC8BEE954EF} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{35ED118C-CAF1-621F-5AC4-587668DD040D} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{3F7A0085-83DF-8EA3-6353-820069149E3B} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{40654D3E-7FC8-AEBB-ABB0-ED82401DD4FB} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{430877C2-C2D8-C656-0597-4411D4BEFDC4} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{4BEEAF00-3590-983E-66F7-8D172B4FF8C4} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{4E108538-403B-4634-4541-625985FC367B} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{5376C008-43E9-B01E-C70A-C935910F0FD2} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{5BCC6952-A400-DA5E-2572-D68C74339A1B} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{5DC8F5E4-E651-4A8F-0C0E-BB293A521172} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{5E5E70C2-E430-0AAF-8ECE-321F9B1C4F50} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{64E2E47A-49FE-6602-0901-F8F3172B36FC} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{6A5CE312-3800-A5E4-E7E0-D6264819E32C} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{745BB346-551B-CC10-8B40-38F74D25A3EB} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{795866A4-7064-4539-4538-2E6CC15F4BED} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{85D99FC8-A44F-68F7-C3BB-8D4B49A8D1B0} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{88278391-118B-BCB6-E08A-964AA5FEF26D} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{8C57E8AD-9376-E315-A81F-1A17FC9316DA} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{8EA0E2B4-988E-7712-5365-EAD96D2B49CC} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{9149118E-88BB-CD35-4317-18A3EAE5881B} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{92B26DF9-71EB-63F5-BEEF-8CC4348A71E7} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{93674FCF-119D-EBAC-174F-9BA8737F9ADD} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{A16C5E7C-DEC1-2CE6-F513-D788EF01513B} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{A171198B-3C34-B625-5E5F-CEC53B8315B3} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{A40D6EDD-39C0-F8EB-2A8D-78A5144A66D0} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{ABE199E3-D9FF-9402-7CDB-478D4A6CB9D9} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{AEE98A84-9A76-BE17-DF76-A88F982D2404} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{B041F9A8-D982-5896-FB80-D72760F801E6} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{BB0058FA-B2CF-E8A4-7D77-15E7458BC241} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{CAC3AE7E-DEF2-72E1-A0C8-DA72B4E1834A} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{D1F0CDB5-E908-7D81-54C6-CCE72BC8C94D} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{DB07E127-DAB0-4DB6-DB26-37706567407D} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{DFC62350-1E0B-BBD2-4CDB-757B623F0FD4} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{E3660349-F68F-6736-8733-F80F0102D728} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{ECE6A683-C89C-4255-3DFA-ACA228B03A79} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{EE2EFEB6-458C-9929-89B7-2B57E8D00712} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\CLSID\{F9538E86-36EE-4A7E-6596-B6F8EAA229D9} -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\SigningModule.SigningModule -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\SigningModule.SigningModule\CLSID -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\SigningModule.SigningModule\CurVer -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\SigningModule.SigningModule.1 -> Adware.Altnet : Cleaned with backup
   HKLM\SOFTWARE\Classes\Sostatatl.StatHTMLCtrl -> Adware.WurldMedia : Cleaned with backup
   HKLM\SOFTWARE\Classes\Sostatatl.StatHTMLCtrl\CLSID -> Adware.WurldMedia : Cleaned with backup
   HKLM\SOFTWARE\Classes\Sostatatl.StatHTMLCtrl\CurVer -> Adware.WurldMedia : Cleaned with backup
   HKLM\SOFTWARE\Classes\Sostatatl.StatHTMLCtrl.1 -> Adware.WurldMedia : Cleaned with backup
   HKLM\SOFTWARE\Classes\Tchk.TChkBHO.1 -> Adware.InetSpeak : Cleaned with backup
   HKLM\SOFTWARE\Classes\WebP2PInstaller.Installer -> Adware.P2PNetworking : Cleaned with backup
   HKLM\SOFTWARE\Classes\WebP2PInstaller.Installer\CLSID -> Adware.P2PNetworking : Cleaned with backup
   HKLM\SOFTWARE\Classes\WebP2PInstaller.Installer\CurVer -> Adware.P2PNetworking : Cleaned with backup
   HKLM\SOFTWARE\Classes\WebP2PInstaller.Installer.1 -> Adware.P2PNetworking : Cleaned with backup
   HKLM\SOFTWARE\Classes\winlink.ViewSource -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\winlink.ViewSource\CLSID -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\winlink.ViewSource\CurVer -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\winlink.ViewSource.1 -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\WinShow.ViewSource -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\WinShow.ViewSource\CLSID -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\WinShow.ViewSource\CurVer -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\Classes\WinShow.ViewSource.1 -> Adware.CoolWebSearch : Cleaned with backup
   HKLM\SOFTWARE\FENX -> Dialer.Generic : Cleaned with backup
   HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup
   HKU\S-1-5-21-93081172-1662961013-3951945890-1006\Software\d78ffc13 -> Adware.CoolWebSearch : Cleaned with backup
   HKU\S-1-5-21-93081172-1662961013-3951945890-1006\Software\d78ffc13\red81542 -> Adware.CoolWebSearch : Cleaned with backup
   HKU\S-1-5-21-93081172-1662961013-3951945890-1006\Software\WinShow -> Adware.CoolWebSearch : Cleaned with backup
   HKU\S-1-5-21-93081172-1662961013-3951945890-1006\Software\WinShow\WinShow -> Adware.CoolWebSearch : Cleaned with backup
   C:\Documents and Settings\Anna\Start Menu\Programs\WeatherCast -> Adware.SaveNow : Cleaned with backup
   C:\Program Files\Altnet -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\dminfo2.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\dminstall3.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\dmsetup.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\dmsetupbig.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\jsinstall.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\jslegals.txt -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\selectdir.txt -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\selectdir.txt1st -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Download Manager\selectdir1st.txt -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.ivd.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cran.cvd.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\altnet.css -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\gradient.gif -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\local_firstuse.html -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\local_points.html -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\local_redeem.html -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\local_start.html -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\local_wallet.html -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\notconnected.gif -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\offline.gif -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\LocalPages\pixel.gif -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\settings.cab -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\back-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\back.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\bottom.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\bottomleft.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\bottomright.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\close-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\close.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\forward-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\forward.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-bottom.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-top.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-topleft.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help-topright.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\help.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\Help.xml -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\left.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\maximise-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\maximise.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_bottom.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_bottomleft.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_bottomright.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_left.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_right.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_top.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_topleft.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\mb_topright.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\message.xml -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\minimise-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\minimise.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\points-disabled.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\points-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\points-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\points.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\redeem-disabled.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\redeem-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\redeem-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\redeem.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\refresh-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\refresh.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\right.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\Sav3BD.tmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\settings-disabled.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\settings-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\settings-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\settings.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\Skin.xml -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\start-disabled.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\start-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\start-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\start.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\top.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\topleft-pro.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\topleft-reg.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\topleft.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\topright.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\wallet-disabled.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\wallet-over.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\wallet-sel.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Skin\wallet.bmp -> Adware.Altnet : Cleaned with backup
   C:\Program Files\Altnet\Points Manager\Temp Internet Shares -> Adware.Altnet : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Addynamix : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Specificpop : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.X10 : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@advertising[1].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@advertising[2].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@atdmt[1].txt.bak -> TrackingCookie.Atdmt : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@atdmt[2].txt.bak -> TrackingCookie.Atdmt : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@bfast[1].txt.bak -> TrackingCookie.Bfast : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@bfast[2].txt.bak -> TrackingCookie.Bfast : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@bluestreak[1].txt.bak -> TrackingCookie.Bluestreak : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Porngraph : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@casalemedia[1].txt.bak -> TrackingCookie.Casalemedia : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@centrport[2].txt.bak -> TrackingCookie.Centrport : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@commission-junction[1].txt.bak -> TrackingCookie.Commission-junction : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitslink : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Coremetrics : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Coremetrics : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@doubleclick[1].txt.bak -> TrackingCookie.Doubleclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@doubleclick[2].txt.bak -> TrackingCookie.Doubleclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@ehg-Email Removedhitbox[1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@ehg-Email Removedhitbox[2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@fastclick[1].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@fastclick[2].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@gator[1].txt.bak -> TrackingCookie.Gator : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@hitbox[1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@hitbox[2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@linksynergy[1].txt.bak -> TrackingCookie.Linksynergy : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@linksynergy[2].txt.bak -> TrackingCookie.Linksynergy : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@mediaplex[1].txt.bak -> TrackingCookie.Mediaplex : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@mediaplex[2].txt.bak -> TrackingCookie.Mediaplex : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@pro-market[1].txt.bak -> TrackingCookie.Pro-market : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@pro-market[2].txt.bak -> TrackingCookie.Pro-market : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@qksrv[1].txt.bak -> TrackingCookie.Qksrv : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@qksrv[2].txt.bak -> TrackingCookie.Qksrv : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@questionmarket[1].txt.bak -> TrackingCookie.Questionmarket : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@questionmarket[2].txt.bak -> TrackingCookie.Questionmarket : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@sexlist[2].txt.bak -> TrackingCookie.Sexlist : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@specificpop[1].txt.bak -> TrackingCookie.Specificpop : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@spylog[1].txt.bak -> TrackingCookie.Spylog : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@spylog[2].txt.bak -> TrackingCookie.Spylog : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@targetnet[2].txt.bak -> TrackingCookie.Targetnet : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@trafficmp[1].txt.bak -> TrackingCookie.Trafficmp : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\anna@trafficmp[2].txt.bak -> TrackingCookie.Trafficmp : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Coremetrics : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Gator : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Adserver : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Specificpop : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@advertising[2].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@atdmt[2].txt.bak -> TrackingCookie.Atdmt : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@bfast[2].txt.bak -> TrackingCookie.Bfast : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@bluestreak[2].txt.bak -> TrackingCookie.Bluestreak : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@centrport[1].txt.bak -> TrackingCookie.Centrport : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@commission-junction[1].txt.bak -> TrackingCookie.Commission-junction : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@doubleclick[1].txt.bak -> TrackingCookie.Doubleclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@fastclick[2].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@hitbox[2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@linksynergy[2].txt.bak -> TrackingCookie.Linksynergy : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@mediaplex[1].txt.bak -> TrackingCookie.Mediaplex : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@qksrv[1].txt.bak -> TrackingCookie.Qksrv : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@revenue[1].txt.bak -> TrackingCookie.Revenue : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@spylog[2].txt.bak -> TrackingCookie.Spylog : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@trafficmp[2].txt.bak -> TrackingCookie.Trafficmp : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@valueclick[1].txt.bak -> TrackingCookie.Valueclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\della@valueclick[2].txt.bak -> TrackingCookie.Valueclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Adserver : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Addynamix : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Addynamix : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Specificpop : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.X10 : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@advertising[1].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@advertising[2].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@atdmt[1].txt.bak -> TrackingCookie.Atdmt : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@atdmt[2].txt.bak -> TrackingCookie.Atdmt : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@bfast[1].txt.bak -> TrackingCookie.Bfast : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@bfast[2].txt.bak -> TrackingCookie.Bfast : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@bluestreak[1].txt.bak -> TrackingCookie.Bluestreak : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@bluestreak[2].txt.bak -> TrackingCookie.Bluestreak : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Porngraph : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Porngraph : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@casalemedia[1].txt.bak -> TrackingCookie.Casalemedia : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@centrport[1].txt.bak -> TrackingCookie.Centrport : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@centrport[2].txt.bak -> TrackingCookie.Centrport : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@commission-junction[1].txt.bak -> TrackingCookie.Commission-junction : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitslink : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@doubleclick[1].txt.bak -> TrackingCookie.Doubleclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@doubleclick[2].txt.bak -> TrackingCookie.Doubleclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@ehg-Email Removedhitbox[1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@ehg-Email Removedhitbox[2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@fastclick[1].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@fastclick[2].txt.bak -> TrackingCookie.Fastclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@gator[1].txt.bak -> TrackingCookie.Gator : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@hitbox[1].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@hitbox[2].txt.bak -> TrackingCookie.Hitbox : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@linksynergy[1].txt.bak -> TrackingCookie.Linksynergy : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@mediaplex[1].txt.bak -> TrackingCookie.Mediaplex : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@mediaplex[2].txt.bak -> TrackingCookie.Mediaplex : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@qksrv[1].txt.bak -> TrackingCookie.Qksrv : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@qksrv[2].txt.bak -> TrackingCookie.Qksrv : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@questionmarket[1].txt.bak -> TrackingCookie.Questionmarket : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@questionmarket[2].txt.bak -> TrackingCookie.Questionmarket : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@revenue[2].txt.bak -> TrackingCookie.Revenue : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Advertising : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@sexlist[1].txt.bak -> TrackingCookie.Sexlist : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@sexlist[2].txt.bak -> TrackingCookie.Sexlist : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@sextracker[1].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@sextracker[2].txt.bak -> TrackingCookie.Sextracker : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@targetnet[2].txt.bak -> TrackingCookie.Targetnet : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@trafficmp[1].txt.bak -> TrackingCookie.Trafficmp : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@trafficmp[2].txt.bak -> TrackingCookie.Trafficmp : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Coremetrics : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@valueclick[1].txt.bak -> TrackingCookie.Valueclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@valueclick[2].txt.bak -> TrackingCookie.Valueclick : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@xxxcounter[1].txt.bak -> TrackingCookie.Xxxcounter : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@xxxcounter[2].txt.bak -> TrackingCookie.Xxxcounter : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@xxxtoolbar[1].txt.bak -> TrackingCookie.Xxxtoolbar : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\jon@xxxtoolbar[2].txt.bak -> TrackingCookie.Xxxtoolbar : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][1].txt.bak -> TrackingCookie.Adserver : Cleaned with backup
   C:\Program Files\SpyHunter\Backup\[email protected][2].txt.bak -> TrackingCookie.Adserver : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_530000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_587200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_587200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_598200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_598300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_599100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_635500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_636400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_636700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_652400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_652600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_654100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_677700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_677700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_686800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_687400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_687400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_699700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_705400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_705400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_765500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_765500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_1_766900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_2_603700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_2_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_2_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_624800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_625800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_626400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_626800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_632500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_703500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_0_3_703500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_525800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_525800.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.swf -> Ad
« Last Edit: June 07, 2006, 07:51:46 PM by darko2021 »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please help me fix this computer
« Reply #5 on: June 07, 2006, 07:59:17 PM »
I'm not seeing the bottom part of the Ewido log
Can you post anything below these entries in the log please
 C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.htm -> Adware.Cydoor : Cleaned with backup
C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.swf -> Ad

Note: I didn't see SpyHunter in your uninstall list, have you uninstalled it?
I don't want you too reinstall it, but if you have uninstalled it
Go ahead and delete this folder
 C:\Program Files\SpyHunter <-this folder

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline darko2021

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
Please help me fix this computer
« Reply #6 on: June 07, 2006, 08:28:21 PM »
C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_528000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_530000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_543700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_543700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_582200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_582200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_587200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_587200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_598200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_598300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_599100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_617000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_617000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_635500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_636400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_636700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_647900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_647900.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_652400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_652600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_654100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_654800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_677700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_677700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_686800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_687400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_687400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_697000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_697000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_699700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_705400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_705400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_725600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_725600.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_734300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_734300.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_760700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_760700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_765500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_765500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_1_766900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_536100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_554200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_561800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_581300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_582600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_599800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_603700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_604400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_604900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_619400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_622500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_623700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_624400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_624700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_630000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_631000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_637300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_637300.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_639600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_639600.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_640500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_640500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_669100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_676700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_678800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_679000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_679300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_679800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_694800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_713300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_713600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_713900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_720700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_721300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_723200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_726100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_727300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_744800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_744800.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_744900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_744900.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_749300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_752900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_753000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_773700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_773700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_773900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_773900.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_775800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_775800.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_779400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_779400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_779500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_2_779500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_525000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_525000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_563600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_577200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_618500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_624100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_624800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_625800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_625900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_626200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_626400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_626800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_628400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_632500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_633800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_633800.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_648500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_654600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_662400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_703500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_703500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_733000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_2_3_754600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_525800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_525800.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_530000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_582200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_582200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_587200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_587200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_598200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_598300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_599100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_635500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_636400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_636700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_652400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_652600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_654100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_654800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_677700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_677700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_686800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_687400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_687400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_699700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_705400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_705400.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_725600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_725600.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_734300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_734300.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_760700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_760700.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_765500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_765500.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_1_766900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_2_723200.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_2_728800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_2_766000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_3_2_766000.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_522800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_546200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_546200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_572200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_572200.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_593200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_631600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_706900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_712000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_1_775400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_508100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_550100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_550200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_574200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_576200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_588600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_588600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_641400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_641400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_699800.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_699800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_699900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_699900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_700600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_713700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_731500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_748500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_748600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_749500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_749900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_750600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_754700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_2_775400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_505000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_615100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_631900.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_631900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_644700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_646300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_680400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_682300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_682300.swf -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_713700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_758000.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_758000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_3_779300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_646100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_646100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650300.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650600.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_650700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_651400.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_651400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_670700.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_670700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_679500.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_679500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_722100.gif -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_329_4_4_722100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_524700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_525900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_526700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_533900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_556700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_557100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_566900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_571200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_580800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_587000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_598500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_599200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_604700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_630100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_635900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_636000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_647400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_647800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_648300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_650200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_655400.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_659300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_662800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_670300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_673200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_684100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_696100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_696700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_705600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_705800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_706000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_706100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_719500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_723000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_723100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_725900.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_735100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_735200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_743600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_743700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_746200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_746300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_746800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_753500.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_754300.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_758100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_763800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_764000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_765800.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_767600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_767700.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_768100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_775000.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_775600.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_779200.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\AdCache\B_780100.htm -> Adware.Cydoor : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\130_45_goldandblue.gif -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-10001-2389510547.sig -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-10001-3432499931.sig -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-10001-800208597.sig -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-5001-2389510547.sig -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-65535-0x45e9aa1a8008c0657eda05c21ff4fdaf.sig -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\index256.dbb -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\P2P Networking.eng -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\P2P Networking.LOG -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\P2P Networking2.ENG -> Adware.P2PNetworking : Cleaned with backup
   C:\WINDOWS\SYSTEM32\P2P Networking\P2P Networking3.ENG -> Adware.P2PNetworking : Cleaned with backup


::Report End
« Last Edit: June 07, 2006, 08:33:12 PM by darko2021 »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Please help me fix this computer
« Reply #7 on: June 07, 2006, 08:52:03 PM »
Good work, the last hijackthis looked good
In addition to Ad-Aware, I would also do the following
Download and Install Spybot 1.4 from
HERE
 or HERE

After installation--Click the UPDATE button on the left
SEARCH FOR UPDATES on the right
Check, and then download all updates
After update is complete
Click the "Search & Destroy" button on the left
"Check for Problems"---When the Scan is complete
FIX all selected promblems in RED

RESTART the computer if any red items were checked and fixed

If everything is running better
We should flush all your restore points as they may be infected
    Go to START>>RUN>>In the open field
    Type in
msconfig
Click OK
Click the "Launch System Restore" button
On the Left hand side click on "System Restore Settings"
Put a Check in "Turn off System Restore"
Apply it and OK out of there>>Reboot your computer
[/list]                          
Back in Windows, Go back and take the check out of "Turn off system restore"
This will reenable the System Restore feature and creates a new restore point

                 [indent][color=\"#CC0000\"]Protect yourself against Future Attacks[/color][/i][/b][/indent]
*Install  SpywareBlaster 3.5.1 by JavaCool  
    *Will block bad ActiveX Controls
    *Block Malevolent cookies in Internet Explorer and Firefox
    *Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates and then click the "Enable all protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"
                   
*Make sure your Anti-Virus software is always kept up to date and actively running in the background

*Keep your Firewall protection enabled
A Firewall is also very important
This provides a line of defense against someone who might try to access your computer without your permission

Update and do scan's with your Anti-Spyware programs on a regular basis
In addition: Open Spybot 1.4
Click the "Immunize" button on the left>>>OK at the prompt>>Immunzine at the top green cross
Immunize after every update

+You may choose to hold onto Ewido
It will become a limited free version after a couple of weeks
Still, a great scanner to update and run on a monthly basis

*Keep up to date on Windows updates (High Priorities)
This is the most important step in keeping your system secure
Make sure you check for updates at least once a month!
you still haven't updated to Service pack 2?
I would take this oppurtunity to update
Please see this link:
http://www.microsoft.com/windowsxp/sp2/default.mspx
Take note on that page and read the following
   [indent]What to know before you download and install[/indent]

Before updating I would run the disk defragmenter on your computer
START>>All Programs>>Accessories>>System Tools>>Disk Defragmenter
If you haven't ran this in awhile, it could take a bit of time to finish, let it run uninterrupted
I find it best ran in safe mode
Then reboot back to Normal mode and visit Windows Updates!
If your on dialup, you may choose to order the free CD
There is a link on that page also

Stay safe  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
« Last Edit: June 07, 2006, 11:29:05 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here