C:\Documents and Settings\fosterbw\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\fosterbw\Local Settings\Temp\b122.exe -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{95EA8C9A-0C92-47FD-9143-A69D427E69E3}\RP366\A0058904.dll -> Adware.SurfSide : Cleaned.

Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo!
does this mean that my downloader has got spyware or malware in it?

Logfile of Trend Micro jackTs v2.0.2 ...
Any other hints on why this is happening and what can be done about it?
C:\Documents and Settings\fosterbw\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.

Offhand, looking at your HiJack log, the worst thing I see is the Wintools entry.
C:\System Volume Information\_restore{95EA8C9A-0C92-47FD-9143-A69D427E69E3}\RP364\A0054712.dll -> Adware.RK : Cleaned.

You will need to have a Windows Vista installation CD or your computer manufacturer will have had to partition a recovery drive on the hard disk.
HKLM\SOFTWARE\Classes\KBBar.KBBarBand.1 -> Adware.PowerStrip : Cleaned.
C:\System Volume Information\_restore{95EA8C9A-0C92-47FD-9143-A69D427E69E3}\RP364\A0055741.exe -> Adware.Softomate : Cleaned.

Let me know if you need any help figuring out how to disable startups or with doing the startup repair.

you can put spybot's hosts file into your own and lock it.

File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0CE40001.VBN tagged as not-a-virus:AdWare.Win32.SearchAssistant.f.
C:\Program Files\Hijackthis\backups\backup-20070411-160445-201.dll -> Adware.BookedSpace : Cleaned.
O2 - BHO: (no name) - {431B2756-641B-40E4-8B98-384AB2D33929} - C:\Program Files\NetWaiting\meqotabo.dll O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{38F96~1\Bar888.dll (file missing)
C:\Documents and Settings\fosterbw\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{95EA8C9A-0C92-47FD-9143-A69D427E69E3}\RP364\A0046607.exe -> Adware.Relevant : Cleaned.

C:\Documents and Settings\fosterbw\Cookies\[email protected][2].txt -> TrackingCookie.Euroclick : Cleaned.
Sep 25, 2005 #2 pkroks TS Rookie Topic Starter Posts: 259 i did wat you said and i deleted the idmmbc.dll file.
Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\ETC Win 98\ME = C:\WINDOWS ie-spyad.Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't