--------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 10:49:32 AM, 6/29/2005 + Report-Checksum: 21C3AD76 + Date of database: 6/29/2005 + Version of scan engine: v3.0 + Duration: 63 min + Scanned Files: 59418 + Speed: 15.50 Files/Second + Infected files: 110 + Removed files: 110 + Files put in quarantine: 110 + Files that could not be opened: 0 + Files that could not be cleaned: 0 + Binder: Yes + Crypter: Yes + Archives: Yes + Scanned items: C:\ + Scan result: C:\Hijack This\backups\backup-20050629-091504-727.dll -> TrojanDownloader.Dyfuca.eg -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0015585.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0015590.exe -> Trojan.Stervis.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0015591.exe -> Trojan.Nail -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0016585.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0016589.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0016593.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP96\A0016594.exe -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0016797.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017806.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017812.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017824.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017825.exe -> Trojan.Nail -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017826.exe -> Trojan.Stervis.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017827.dll -> Trojan.Agent.db -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017832.exe -> Spyware.PurityScan -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017833.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017834.EXE -> Spyware.WeirWeb -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017835.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017836.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017837.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017838.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017839.exe -> Spyware.BargainBuddy -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017840.exe -> Not-A-Virus.Hoax.Renos.a -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017841.EXE -> TrojanDownloader.Adload.a -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017842.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017843.EXE -> Not-A-Virus.Hoax.Renos.a -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017844.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017845.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017846.exe -> Spyware.BetterInternet.f -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017847.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017848.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017849.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017850.EXE -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017851.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017852.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017853.DLL -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017854.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017855.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017856.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017857.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017858.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017859.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017860.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017861.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017862.DLL -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017863.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017864.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017865.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017866.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017867.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017868.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017869.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017870.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017871.DLL -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017872.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017873.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017874.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017875.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017876.DLL -> Trojan.Agent.db -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017877.exe -> Spyware.BetterInternet.f -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017878.DLL -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017879.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017880.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017881.EXE -> Trojan.WebSearch.i -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017882.DLL -> Trojan.WebSearch.j -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017883.DLL -> Spyware.SmartPops -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017884.exe -> Spyware.BetterInternet.f -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017885.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017886.DLL -> Trojan.Agent.db -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017887.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017888.EXE -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017889.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017890.EXE -> Spyware.SmartPops -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017891.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017892.exe -> Spyware.BetterInternet.f -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017893.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017894.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017895.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017896.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017897.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017898.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017899.exe -> Spyware.BetterInternet -> Cleaned with backup C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP97\A0017900.dll -> TrojanDownloader.Dyfuca.eg -> Cleaned with backup C:\WINDOWS\SSK3_B5.exe -> TrojanDropper.Small.qn -> Cleaned with backup C:\WINDOWS\sys3553.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys3554.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys3615.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys3617.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys367.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys368.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys4857.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys4859.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\sys491.exe -> Trojan.Crypt.c -> Cleaned with backup C:\WINDOWS\systb.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\WINDOWS\SYSTEM\svchosthook.dll -> Backdoor.Agent.iw -> Cleaned with backup C:\WINDOWS\SYSTEM32\idiiqsq4.dll -> Spyware.SAHA -> Cleaned with backup C:\WINDOWS\SYSTEM32\maxd.exe -> Dialer.Generic -> Cleaned with backup C:\WINDOWS\SYSTEM32\memach.exe -> Spyware.BetterInternet -> Cleaned with backup C:\WINDOWS\SYSTEM32\thn32.dll -> TrojanProxy.Small.bk -> Cleaned with backup C:\WINDOWS\SYSTEM32\vxgamet1.exe -> TrojanDownloader.Small.aqt -> Cleaned with backup C:\WINDOWS\SYSTEM32\vxgamet2.exe -> Trojan.LowZones.y -> Cleaned with backup C:\WINDOWS\SYSTEM32\vxh8jkdq5.exe -> TrojanDownloader.Small.awa -> Cleaned with backup C:\WINDOWS\SYSTEM32\web.exe -> TrojanDownloader.Small.agq -> Cleaned with backup C:\WINDOWS\SYSTEM32\ѕνchost.exe -> Spyware.PurityScan -> Cleaned with backup C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\WINDOWS\ucggsuip.exe -> Spyware.SAHA -> Cleaned with backup C:\WINDOWS\urwmoclkrcr.exe -> Spyware.BetterInternet -> Cleaned with backup C:\WINDOWS\wupdsnff.exe -> Spyware.BetterInternet.f -> Cleaned with backup C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup ::Report End