Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I get a pop up box asking if I wish to run an application file entitles behucnxvod.exe which it states is from Windows/System 32.
I have ran several searches on the system to try and locate a file of this name and also searched various virus killer sites to see if it is listed. I do not want to run it as I do not know what it is. Mt neice and daughter were recently on MSN 7 chatting and exchanging downloads and it is possibly from one of them.
Anyone got any ideas as to what this is?
Cheers - Bryn

Try uploading the file to this link http://virusscan.jotti.org/ then post the results please.

I have not run the file in question yet as I do not know what the consequences will be. I am therefore unable to do as you suggest. I did go online with virusscan/jotti and typed the name in but nothing happened.
Cheers - Bryn

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.
Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.
Run this free online scan from Panda
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to the desktop, then copy/paste into the text editor and post it.

Logfile of HijackThis v1.99.1
Scan saved at 18:35:25, on 19/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\sistray.exe
C:\WINDOWS\SOUNDMAN.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\WINDOWS\system32\WLANSTA.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Inventel\Gateway\WLANCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll (file missing)
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.exe START
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Recylinder Check] behucnxvod.exe
O4 - HKLM\..\RunServices: [Windows Recylinder Check] behucnxvod.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WLAN network adaptor Wireless LAN Configuration.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-18.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123355493093
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssiPictureUploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exeCheers - Bryn

The Panda scan results would be helpful.
I would suggest that you uninsatall "limewire", as it is known to harbor spyware, untill your system is clean at least. There are p2p programs that are spyware free.
Although I don't see "Vundo" files there are files associated with it. So please download http://www.atribune.org/public-beta/VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ We will need it later in safe modeDownload Ewido Security Suite then set it up this way Ewido Setup Instructions We will need this later in safe mode
Be sure to update ewido
Download killbox to your desktop from this link Killbox We will need it later in safe mode
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Run Hijack This from safe mode, close all windows except HT, place a check to the left of the following items and press "fix checked":
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [Windows Recylinder Check] behucnxvod.exe
O4 - HKLM\..\RunServices: [Windows Recylinder Check] behucnxvod.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (If you decided to uninstall it)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll
Exit Hijack This
Run ewido from safe mode and let it delete all that it finds.
Rub ATF-Cleaner. Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Double-click on Killbox.exe to run it.
Put a tick by Standard File Kill.
In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time.C:\WINDOWS\System32\behucnxvod.exe
C:\WINDOWS\behucnxvod.exe
Click on the button that has the red circle with the X in the middle after you enter each file.
It will ask for confimation to delete the file.
Click Yes.
Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.Do a manual search for "behucnxvod.exe" and delete all instances found.
Then if you decided to get rid of limewire navigate to and delete this folder:
C:\Program Files\Limewire
Please post a Panda log and a new Hijack THis log.

Each time I tried to run the panda software Avast stopped it stating there was a worm called as5free/motor.cab\pskavs.DLL
Is this just an advertising pop up?
Cheers - Bryn

Here is the Panda scan before anything other than Limewire removal is done.
Incident Status Location
Adware:adware/otx Not disinfected Windows Registry
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.bfast.com/]
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.xmts.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.advertising.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.paypopup.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.overture.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.centrport.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.linksynergy.com/]
Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.www.intelli-tracker.com/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[counter.hitslink.com/]
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.adviva.net/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Bilbo.counted Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[bilbo.counted.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.tickle.com/]
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Netster Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[lb3.netster.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@112.2o7[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Cookies\amy@247realmedia[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@2o7[2].txt
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@64.62.232[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@888[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Amy\Cookies\amy@ad.yieldmanager[1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adopt.hbmediapro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adrevolver[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Amy\Cookies\amy@ads.pointroll[2].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adtech[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adultfriendfinder[1].txt
Spyware:Cookie/Adverserve Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adverserve[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Amy\Cookies\amy@apmebf[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Amy\Cookies\amy@as-eu.falkag[2].txtCheers - Bryn

From your Panda log it doesn't look like Ewido was run from safe mode as all the cookies normally removed are still there.
Make sure you setup ewido as per the instructions, then update it.
Reboot into safe mode and run Ewido. When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop.
Please reboot into normal mode and post the ewido log on your desktop and a new Hijack This log.

Logfile of HijackThis v1.99.1
Scan saved at 23:13:01, on 20/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.exe
C:\WINDOWS\system32\LEXPPS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\sistray.exe
C:\WINDOWS\SOUNDMAN.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\WLANSTA.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll (file missing)
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.exe START
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WLAN network adaptor Wireless LAN Configuration.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-18.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123355493093
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssiPictureUploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
----------------------
To help you stay safe and secure online, we've developed the all new Yahoo! Security Centre.
----------------------Incident Status Location
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@64.62.232[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@888[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adopt.hbmediapro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adrevolver[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adultfriendfinder[1].txt
Spyware:Cookie/Adverserve Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adverserve[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Amy\Cookies\amy@apmebf[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Amy\Cookies\amy@atwola[1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Amy\Cookies\amy@banner[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Amy\Cookies\amy@belnk[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Amy\Cookies\amy@bravenet[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Amy\Cookies\amy@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Amy\Cookies\amy@cgi-bin[5].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Amy\Cookies\amy@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Amy\Cookies\amy@dist.belnk[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Amy\Cookies\amy@errorsafe[1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Amy\Cookies\amy@fortunecity[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Amy\Cookies\amy@hc2.humanclick[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Amy\Cookies\amy@i.screensavers[2].txt
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Amy\Cookies\amy@landing.domainsponsor[1].txt
Spyware:Cookie/Netster Not disinfected C:\Documents and Settings\Amy\Cookies\amy@lb3.netster[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Amy\Cookies\amy@maxserving[2].txt
Spyware:Cookie/Qsrch Not disinfected C:\Documents and Settings\Amy\Cookies\amy@qsrch[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Cookies\amy@realmedia[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@rn11[1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Amy\Cookies\amy@tickle[1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Amy\Cookies\amy@winfixer[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www.errorsafe[1].txt
Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www.intelli-tracker[1].txt
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www47.buydomains[1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www48.seeq[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Amy\Cookies\amy@xiti[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Amy\Cookies\amy@xmts[2].txt
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Documents and Settings\Amy\Local Settings\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\Cache\1E335A21d01Panda Log
Incident Status LocationSpyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@64.62.232[2].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@888[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adopt.hbmediapro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adrevolver[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adultfriendfinder[1].txt
Spyware:Cookie/Adverserve Not disinfected C:\Documents and Settings\Amy\Cookies\amy@adverserve[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Amy\Cookies\amy@apmebf[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Amy\Cookies\amy@atwola[1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Amy\Cookies\amy@banner[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Amy\Cookies\amy@belnk[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Amy\Cookies\amy@bravenet[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Amy\Cookies\amy@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Amy\Cookies\amy@cgi-bin[5].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Amy\Cookies\amy@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Amy\Cookies\amy@dist.belnk[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Amy\Cookies\amy@errorsafe[1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Amy\Cookies\amy@fortunecity[1].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Amy\Cookies\amy@hc2.humanclick[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Amy\Cookies\amy@i.screensavers[2].txt
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Amy\Cookies\amy@landing.domainsponsor[1].txt
Spyware:Cookie/Netster Not disinfected C:\Documents and Settings\Amy\Cookies\amy@lb3.netster[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Amy\Cookies\amy@maxserving[2].txt
Spyware:Cookie/Qsrch Not disinfected C:\Documents and Settings\Amy\Cookies\amy@qsrch[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Amy\Cookies\amy@realmedia[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Amy\Cookies\amy@rn11[1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Amy\Cookies\amy@tickle[1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Amy\Cookies\amy@winfixer[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www.errorsafe[1].txt
Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www.intelli-tracker[1].txt
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www47.buydomains[1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Amy\Cookies\amy@www48.seeq[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Amy\Cookies\amy@xiti[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Amy\Cookies\amy@xmts[2].txt
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Documents and Settings\Amy\Local Settings\Application Data\Mozilla\Firefox\Profiles\safd9v5w.default\Cache\1E335A21d01
Cheers - Bryn

Please navigate to and delete the contents of this folder:
C:\Documents and Settings\Amy\Cookies
Then navigate to and delete the contents of the firefox cookie cache. To remove all cookies, go to "Tools -> Options -> Privacy -> Cookies" and click "Clear Cookies Now".
Please run Hijack This>click the "open misc tools section" button> click "open uninstall manager">click save list >save >copy/paste this into your next post.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |