Here:
Logfile of HijackThis v1.99.1
Scan saved at 5:23:42 PM, on 6/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\WINDOWS\System32\WLANSTA.EXE
C:\WINDOWS\System32\Atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM95\aim.exe
C:\Documents and Settings\newlaptop\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.buf.adelphia.net:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: SU Toolbar Helper - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\WINDOWS\DOWNLO~1\STUMBL~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Stumble&Upon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\DOWNLO~1\STUMBL~1.DLL
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINDOWS\enhupdt.exe
O4 - HKLM\..\Run: [mptzmk] c:\windows\system32\ujuxxj.exe r
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\WINDOWS\DOWNLO~1\STUMBL~1.DLL/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Literati -
http://download.game...nts/y/tt2_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/potd_x.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -
http://www.webshots....SDownloader.ocxO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1111964754758O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {95844941-7934-4693-92D9-8202EA7B20ED} -
http://www.stumbleupon.com/stumble.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
http://chat.yahoo.com/cab/yvwrctl.cabO16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) -
http://fdl.msn.com/p.../v13/ticker.cabO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: OPCEnum - Unknown owner - C:\Program Files\Common Files\OPC Foundation\OPCENUM.EXE (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Incident Status Location
Adware:Adware/nCase No disinfected C:\WINDOWS\System32\FLEOK
Adware:Adware/KeenValue No disinfected C:\WINDOWS\System32\drivers\etc\hosts.bho
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\System32\in10b6s.dll
Adware:Adware/SAHAgent No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\WINDOWS\alchem.???
Adware:Adware/IEPlugin No disinfected Windows Registry
Adware:Adware/Transponder No disinfected C:\WINDOWS\LastGood\INF\dlmax.PNF
Adware:Adware/DiyToolbar No disinfected Windows Registry
Virus:W32/Bagle.BL.worm Disinfected Local Folders\Deleted Items\Delivery by mail\[upd02.com]
Virus:Trj/W32.Webber Disinfected Personal Folders\Deleted Items\Re: Your E-Loan Refinance Application\E-Loan-Appraiser-Results.pif
Virus:Trojan Horse Disinfected Personal Folders\Deleted Items\Re: Wells Fargo Bank New Business Account Application - ID# 4489\wellsfargo.com.jsessionid=5QWBU8TLSM01.pif
Virus:Trj/Tofger.H Disinfected Personal Folders\Deleted Items\Online Order Confirmation\SecurityPatch_v.3.0.exe
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\test\document.zip[document.txt .pif]
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Mail Delivery System\document.zip[document.scr]
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Mail Delivery System\readme.zip[readme.doc .scr]
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Test\document.zip[document.scr]
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Server Report\document.zip[document.exe]
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\message.scr
Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Warning: could not send message for past 4 hours\Error\file.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\fake?\class_photos.zip[class_photos.htm.exe]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\believe me\number_phone_pic.zip[number_phone_pic.txt.com]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\i've found it about you\id.txt.pif
Virus:W32/Netsky.D.worm Disinfected Personal Folders\Deleted Items\Re: Thanks!\message_part2.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\notice!\myaunt.zip[myaunt.txt.scr]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\abuse?\disco.zip[disco.exe]
Virus:W32/Netsky.D.worm Disinfected Personal Folders\Deleted Items\Re: Your music\mp3music.pif
Virus:W32/Netsky.D.worm Disinfected Personal Folders\Deleted Items\Re: Excel file\document_excel.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\Re: information\aboutyou.htm.com
Virus:W32/Netsky.D.worm Disinfected Personal Folders\Deleted Items\Re: Hi\your_file.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\report\tear.zip[tear.pif]
Virus:W32/Netsky.D.worm Disinfected Personal Folders\Deleted Items\Re: Your document\your_document.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\fake?\class_photos.zip[class_photos.htm.exe]
Virus:W32/Bagle.D.worm Disinfected Personal Folders\Deleted Items\Camila\dadacc.zip[pocewwxq.exe]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\what's up?\posting.zip[posting.scr]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\question\story.zip[story.scr]
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\report\image_tear.pif
Virus:W32/Netsky.C.worm Disinfected Personal Folders\Deleted Items\stolen\dinner.pif
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Re: Thank you\product.zip[product.rtf .scr]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Warning\list.zip[list.htm .scr]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Thank you\details.zip[details.gif .scr]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\LOVE IS...\me.zip[me.htm .pif]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Your credit card\mail.zip[mail.png .pif]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Information\data.zip[data.htm .scr]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Your request is being processed\readme.zip[readme.htm .scr]
Virus:W32/Mydoom.F.worm Disinfected Personal Folders\Deleted Items\Re: Details\website.zip[website.gif .exe]
Virus:W32/Bagle.pwdzip Disinfected Personal Folders\Deleted Items\Re: Incoming Message\Text.zip
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:23:22 AM, 6/25/2005
+ Report-Checksum: CAEB54B1
+ Date of database: 6/24/2005
+ Version of scan engine: v3.0
+ Duration: 301 min
+ Scanned Files: 145298
+ Speed: 8.04 Files/Second
+ Infected files: 64
+ Removed files: 64
+ Files put in quarantine: 64
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\WINDOWS\SYSTEM32\pywurd.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\wjqcwyohi.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\newlaptop\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\newlaptop\Cookies\newlaptop@p[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037620.dll -> Spyware.180solutions -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037621.exe -> Spyware.VirtualBouncer.d -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037622.dll -> TrojanDropper.Small.xm -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037623.dll -> TrojanDownloader.Rameh.c -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037624.exe -> TrojanDownloader.OneClickNetSearch.h -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037625.dll -> Spyware.NoName -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037626.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037627.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037628.exe -> Spyware.NoName.f -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037629.exe -> Spyware.NoName -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037630.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037632.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037633.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037634.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037635.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037640.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037645.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037646.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037647.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037792.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037796.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0037918.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039086.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039292.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039294.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039362.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039363.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP182\A0039365.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0039670.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0039913.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0039972.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0040554.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0040612.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0040759.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0041077.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0041079.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0041085.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0041091.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP184\A0041117.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP185\A0041963.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP185\A0041970.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP186\A0041976.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP187\A0042976.EXE -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043123.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043133.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043134.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043135.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043136.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{FE66E168-0014-4B61-81AF-FACCFC18D304}\RP188\A0043137.dll -> Trojan.Agent.db -> Cleaned with backup
C:\Recycled\NPROTECT\00005857.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00007105.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00007107.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00008618.EXE -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00009277.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00009829.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00009840.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00005534.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\NPROTECT\00005617.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Recycled\Dc31\Norton Internet Security 2005\KEY-GENERATOR NIS 2005\NIS 2005 - Keygen SSG.exe -> TrojanDropper.Delf.fd -> Cleaned with backup
C:\Recycled\Dc31\NORTON KEY-GENERATORS\KeyGens Norton 2005\NIS 2005 - Keygen SSG.exe -> TrojanDropper.Delf.fd -> Cleaned with backup
::Report End