Ewido Log---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:43:11 PM 10/24/2006
+ Scan result:
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106532.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106533.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106534.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106535.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106536.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106537.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106538.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106539.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106540.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106541.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106542.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106543.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106544.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106545.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106546.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106547.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106548.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106549.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP16\A0141739.dll -> Adware.Searchcolours : Cleaned with backup (quarantined).
C:\Program Files\Deskbar -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\about.html -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\basis.xml -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\deskbar.crc -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\deskbar.inf -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\icons.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\inst.bat -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mbback.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mbbigopen.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mbclose.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mbfwd.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mblogo.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\mbsep.bmp -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\options.html -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\softomate.gif -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Deskbar\version.txt -> Adware.Softomate : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DBTB00001.DBTB00001Deskbar -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP15\A0140712.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP15\A0141707.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP16\A0141732.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP17\A0145751.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP17\A0146757.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP17\A0147783.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP17\A0147784.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\WINDOWS\system32\.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__n_e_t_3_2_b_._e_x_e_ -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\WINDOWS\system32\net32b.exe -> Backdoor.IRCBot.st : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106530.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP3\A0008112.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP4\A0014141.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP7\A0037299.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0040306.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0043324.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0045335.exe -> Backdoor.Rbot.biu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP36\A0250068.exe -> Backdoor.Rbot.bkj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\iexplorere.exe -> Backdoor.Rbot.bkj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0056439.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0057437.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0058437.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0058465.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0059467.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0060462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0061462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0063462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0064462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0065469.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0066462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0067466.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0069462.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0069479.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0070479.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0072475.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0075475.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0084476.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0085478.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0086484.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0088483.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0089486.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0090483.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0090490.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP11\A0092494.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106521.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106522.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106523.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106524.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP15\A0140711.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP20\A0158869.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP21\A0167207.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP25\A0187356.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0045334.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0045345.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP8\A0045353.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP9\A0046355.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP9\A0046364.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP9\A0047375.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP9\A0048373.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\WINDOWS\system\msidll.exe -> Backdoor.SdBot.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP21\A0166358.exe -> Backdoor.SdBot.aya : Cleaned with backup (quarantined).
C:\WINDOWS\lsass.exe_tobedeleted -> Backdoor.SdBot.aya : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP36\A0250067.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP36\A0250090.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\x.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\WINDOWS\system\dllhost.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\WINDOWS\system\winlogon.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106519.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106520.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0098494.exe -> Downloader.Agent.awg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0100494.exe -> Downloader.Agent.awg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0104507.exe -> Downloader.Agent.awg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP16\A0141724.dll -> Downloader.Agent.awg : Cleaned with backup (quarantined).
[776] VM_007D0000 -> Downloader.Agent.uj : Error during cleaning.
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106529.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\cvvrc.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106513.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106514.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106552.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106561.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP13\A0107552.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP13\A0107553.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP13\A0113619.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP15\A0140709.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP16\A0141731.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP17\A0147782.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP20\A0159968.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP25\A0187355.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP30\A0219442.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP31\A0231583.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP31\A0231585.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP31\A0231586.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__j_o_j_q_u_n_._e_x_e_ -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jojqun.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\pmyth.dat -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP30\A0221479.vbs -> Downloader.Small.az : Cleaned with backup (quarantined).
C:\Program Files\Common Files\uqrk\uqrkd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP3\A0008129.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP4\A0016153.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP10\A0059468.exe -> Not-A-Virus.SpamTool.Win32.Agent.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP12\A0106550.exe -> Not-A-Virus.SpamTool.Win32.Agent.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP4\A0016136.sys -> Rootkit.Agent.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP4\A0016152.sys -> Rootkit.Agent.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP5\A0027231.sys -> Rootkit.Agent.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP9\A0048377.sys -> Rootkit.Agent.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP33\A0240760.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{426FD903-708C-4867-9AFE-30F76C364197}\RP36\A0250089.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmbrl.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
::Report end
HJT LogLogfile of HijackThis v1.99.1
Scan saved at 5:50:03 PM, on 10/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.gatewaybiz.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Ms Update WinServices NT/XP] winservnt32.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{291772FA-81F2-468B-A9A7-DA2EAD895494}: NameServer = 85.255.114.36,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{382F7B25-A939-4A93-B840-164DCDE901D1}: NameServer = 85.255.114.36 85.255.112.23
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.36 85.255.112.23
O17 - HKLM\System\CS1\Services\Tcpip\..\{291772FA-81F2-468B-A9A7-DA2EAD895494}: NameServer = 85.255.114.36,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.36 85.255.112.23
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: COM+ System Service (DLLHOST) - Unknown owner - C:\WINDOWS\system\dllhost.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft information dll service (msidll) - Unknown owner - C:\WINDOWS\system\msidll.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Microsoft Windows Internet Connections Manager (net32b) - Unknown owner - C:\WINDOWS\System32\net32b.exe (file missing)
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Microsoft sdk core (sdk) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows NT Logon Application (WINLOGON) - Unknown owner - C:\WINDOWS\system\winlogon.exe (file missing)
Thanks alot