Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:06:30 PM, on 1/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure\FSGUI\fsguiexe.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Setup.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\INSNTMSI.EXE
C:\WINDOWS\system32\dumprep.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Sonic INSTALLit! Setup.lnk = C:\Documents and Settings\Russ\Local Settings\Temp\VIES535D\Setup.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1200350479340
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
--
End of file - 6468 bytes
Incident Status Location
Virus:Trj/Downloader.PLF Disinfected C:\install.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0059002.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0059003.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0059004.exe
Virus:Bck/VBBot.C Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059119.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059162.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059163.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059164.exe
Virus:Bck/VBBot.C Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059170.exe
Spyware:Spyware/Vundo Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059171.0XE
Adware:Adware/AdRotator Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059176.dll
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059785.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059786.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059787.exe
Spyware:Spyware/Vundo Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059789.0XE
Adware:Adware/Yazzle Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059795.0XE
Virus:Trj/Popopo.A Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059854.0XE
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059855.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059856.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059857.exe
Adware:Adware/Yazzle Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059863.0XE
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059887.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059888.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059889.exe
Adware:Adware/Yazzle Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059896.0XE
Adware:Adware/Yazzle Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059903.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060298.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060313.0LL
Virus:Trj/Popopo.A Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060315.0XE
Virus:Bck/VBBot.C Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060316.exe
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060320.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060321.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060322.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060323.0XE
Spyware:Spyware/Virtumonde Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060324.0XE
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060333.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060334.exe
Virus:Bck/VBBot.C Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060335.exe
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060336.exe
Virus:Generic Malware Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060340.exe
Adware:Adware/DollarRevenue Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060347.dll
Adware:Adware/Yazzle Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060362.exe
Adware:Adware/PurityScan Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060363.0XE
Adware:Adware/DollarRevenue Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060573.dll
Virus:Trj/Vb.TT Disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060581.exe
Adware:Adware/InternetSpeedMonitor Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060947.exe
Adware:Adware/Adband Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060948.dll
Possible Virus. Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060949.exe
Adware:Adware/InternetSpeedMonitor Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060953.exe[QdrPack11.exe]
Virus:Trj/Downloader.PLF Not disinfected C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061083.0XE[ardCo071084.exe]
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/21/2008 at 08:41 PM
Application Version : 3.9.1008
Core Rules Database Version : 3384
Trace Rules Database Version: 1378
Scan type : Complete Scan
Total Scan Time : 02:44:52
Memory items scanned : 400
Memory threats detected : 0
Registry items scanned : 3848
Registry threats detected : 0
File items scanned : 55184
File threats detected : 27
Adware.ClickSpring/Outer Info Network
C:\Program Files\Outerinfo\OiUninstaller.exe
C:\Program Files\Outerinfo
Adware.Unknown Origin
C:\PROGRAM FILES\COMMON FILES\OWFR\OWFRD\CLASS-BARREL
Unclassified.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059175.DLL
Trojan.Unclassified/PackedInstaller
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059794.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060342.EXE
Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059844.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060314.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060325.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060328.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060329.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060330.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP952\A0064026.DLL
Adware.SprtAds/AdRotator
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059845.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP942\A0059938.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060283.DLL
Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060295.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP949\A0062493.DLL
Trojan.Downloader-Gen/BundleBase
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060338.EXE
RelevantKnowledge Spyware Component
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060349.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060350.DLL
TargetSaver, Inc. Process
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060361.EXE
Adware.AdSponsor/ISM
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060950.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060951.EXE
Unclassified.Unknown Origin/System
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F96AE63F-3B5B-4B3A-AC63-55D381DD3B2B}\RP19\A0005573.DLL
Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{F96AE63F-3B5B-4B3A-AC63-55D381DD3B2B}\RP19\A0005574.EXE
C:\WINLOGON.EXE
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 4:53:29 AM 1/21/2008
+ Scan result:
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060348.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\owfrd\owfrc.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP930\A0059869.0XE -> Downloader.Adload.ni : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059909.0XE -> Downloader.Adload.ni : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060317.exe -> Downloader.Adload.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060579.exe -> Downloader.Agent.buo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059907.exe -> Downloader.Agent.cbx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060303.exe -> Downloader.Agent.cbx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP941\A0059925.exe -> Downloader.Agent.epl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP930\A0059868.exe -> Downloader.Agent.erf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061094.exe -> Downloader.Agent.erf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059910.exe -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060306.exe -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059913.exe -> Downloader.Agent.fjn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060309.exe -> Downloader.Agent.fjn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060305.exe -> Downloader.Agent.fjv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059360.exe -> Downloader.Agent.gat : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059361.exe -> Downloader.Agent.gat : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060310.exe -> Downloader.Agent.gat : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060294.0XE -> Downloader.Agent.gdi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060311.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060312.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059908.exe -> Downloader.Agent.gxj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060307.exe -> Downloader.Agent.hbd : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Desktop\Don\My Documents\Μіcrosoft\WUAUCLT.0XE -> Downloader.PurityScan.fa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059911.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061088.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061095.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\owfrp.0xe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061084.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\owfrd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\owfra.0xe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061086.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\OWFRM.0XE -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061075.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\Program Files\Common Files\owfr\owfrl.0xe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061085.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060326.exe -> Downloader.VB.ccs : Cleaned with backup (quarantined).
C:\Program Files\Words\UnInstall.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\Words\Words.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060946.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060952.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP926\A0059317.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP927\A0059336.dll -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP927\A0059337.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059353.dll -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059354.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059376.dll -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059377.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059772.dll -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP941\A0059919.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060293.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060331.dll -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP939\A0059914.exe -> Not-A-Virus.Adware.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060304.exe -> Not-A-Virus.Adware.Rond : Cleaned with backup (quarantined).
C:\Program Files\TTX.exe -> Not-A-Virus.Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP925\A0059294.dll -> Not-A-Virus.Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060332.dll -> Not-A-Virus.Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060339.exe -> Not-A-Virus.Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060341.exe -> Not-A-Virus.Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0058990.dll -> Not-A-Virus.Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0058991.dll -> Not-A-Virus.Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP923\A0058992.exe -> Not-A-Virus.Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP926\A0059322.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP927\A0059342.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059359.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059382.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP941\A0059924.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060327.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP952\A0065030.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060352.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP950\A0062913.exe -> Not-A-Virus.PSWTool.Win32.FirePass.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060607.sys -> Rootkit.Agent.sg : Cleaned with backup (quarantined).
C:\Documents and Settings\Russ\Cookies\[email protected][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Russ\Cookies\[email protected][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP924\A0059011.0XE -> Trojan.Agent.crf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061087.exe -> Trojan.Pakes.bvs : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP926\A0059320.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP927\A0059340.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP928\A0059357.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP929\A0059380.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP941\A0059922.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP944\A0060351.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP946\A0060853.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061061.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061062.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061089.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061090.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061091.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061092.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{743A5A71-0AFE-488E-AA64-978180A4CE55}\RP947\A0061093.exe -> Trojan.Whispy.a : Cleaned with backup (quarantined).
::Report end
I thank you in advance for any help I can get. I am a newbie to this sort of thing, so I am sorry if I have left anything out or given too much information.
Thanks,
Russ