I got such fantastic help for my last post re: the aurora spyware, etc, that I am back again. Unfortunatley, my second co-workers computer appears to be infected as well.
I have followed the suggested steps before posting and below is my HijackThis Log, as well as my Ewido log.
Any help will be greatly appreciated!!
grrlpwr
HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 7:58:45 PM, on 6/30/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\America Online 7.0\aoltray.exe
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1120173946718
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.googl...n/GoogleNav.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.googl...gleActivate.cab
O16 - DPF: {D6E66235-7AA6-44ED-A06C-6F2033B1D993} - http://146.82.109.20...tion/msiein.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Ewido Log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 7:12:29 PM, 6/30/2005
+ Report-Checksum: 1EAA5D6
+ Date of database: 6/30/2005
+ Version of scan engine: v3.0
+ Duration: 24 min
+ Scanned Files: 59937
+ Speed: 41.62 Files/Second
+ Infected files: 130
+ Removed files: 130
+ Files put in quarantine: 130
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\aclu\Local Settings\Temp\temp.frB34F -> Trojan.Imiserv.c -> Cleaned with backup
C:\Documents and Settings\aclu\Local Settings\Temp\temp.frFCDE -> Trojan.Agent.db -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\130190AE-1A30-454B-A327-A8ED79\661BA06A-B095-41F1-8862-F8E5EE -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\13D30EC1-692B-4813-BC18-DED8F8\4524EBED-88D2-4CC3-88F6-62EA16 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\18288D23-0692-4B7C-9527-63E1FF\015B6CFC-AC80-4602-8BDD-88BD95 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\186F389E-BD75-43A1-94D5-C9058E\13C4FA52-62CC-4654-89E9-4EB437 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\1CCF2229-D189-4560-BEFD-812525\6FEEBC8C-E674-4408-9638-127EDD -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\1DD31F8A-3B16-4A06-9249-FA6468\6B6EFCBD-9EE2-4BB2-8F01-BF2925 -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\1DD31F8A-3B16-4A06-9249-FA6468\CB571691-59A2-4A4F-AD50-867DA5 -> Spyware.ImiBar.d -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\33CA90C2-D53C-4C9A-8140-94C6A7\AA385F3C-3B4C-44FA-B3AE-502DE0 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\34858D1E-83FA-47DB-8507-4DB1BC\7C5E24DE-8B8F-4E60-8F45-E1FB4E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\34858D1E-83FA-47DB-8507-4DB1BC\F6969DE8-243C-447A-A758-2C6FA2 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\3DD40472-F4B3-4F95-BA94-768936\857B5D90-E1C9-405D-955F-0978A6 -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\3DD40472-F4B3-4F95-BA94-768936\D89F1A86-86FE-4550-B38A-260AF4 -> Spyware.ImiBar.d -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\41DC7297-A989-42B3-B3A8-778B27\9EBE750A-DC4C-4319-99B6-9E3DC0 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\4E740DD8-E7B3-4E21-8FA2-9E52E8\67B4187C-94BD-4676-8F98-A9D0FE -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\52286FFB-A270-436B-867E-33C094\1AFFF4C3-DB72-4DFA-B3AD-4AE85E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\52349761-003D-4E70-A6DC-AB0BE7\1F8329BF-AF46-4622-B044-3F64BF -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\52349761-003D-4E70-A6DC-AB0BE7\4A502E75-8821-4C1F-83EA-BEAB49 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\52349761-003D-4E70-A6DC-AB0BE7\E2595975-D044-426D-A40C-146F1E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\55CB0EC2-7604-4841-95D2-7B25F4\22D890A9-938C-4119-952B-58F59B -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\56F97433-A020-4819-878B-5C2911\FFFF588B-22A9-4447-982A-E9986D -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\5E7BA007-A1A3-4A0C-A779-ACDCFF\577D9AE8-9263-434C-9FAF-D4E9E6 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\5E7BA007-A1A3-4A0C-A779-ACDCFF\DD66139B-F0F6-48A6-B0FC-B291D7 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\5E991551-335E-45ED-BDFF-8FA235\EC4DA7A7-E2D1-456C-95D1-7B375A -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\62CECF8F-EB7E-40F6-AE95-E03755\0B06906F-9091-4688-ACB6-1BE264 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\6309D691-56FD-481B-BF33-37EC58\2F92A353-06A7-43B5-A406-3F5AB3 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\6614290D-4045-46B1-9551-5C4113\F849B936-300E-4C39-8F22-8422CA -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\86B53379-FE47-4E3F-B78D-F55085\39030B4A-4A7F-46A5-9AD3-675BD7 -> Trojan.Nail -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\86B53379-FE47-4E3F-B78D-F55085\5580490D-7F9A-42C3-83A3-6493BD -> Trojan.Stervis.c -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\86B53379-FE47-4E3F-B78D-F55085\8703B4D8-B4C4-41DF-907C-BAF287 -> Trojan.Nail -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\91390161-B34E-4CB7-AB94-782A16\A0C0EC08-9CCE-4FCE-952C-E6644E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\933BFFE2-1242-4205-84A6-63011B\41C079BC-6C8C-4746-B47C-FE0C6F -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\95654D96-6480-4578-8CEB-735013\08045EAE-C02A-44DC-A5E5-C42E4F -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\95654D96-6480-4578-8CEB-735013\6DDB8B78-2930-47E7-8801-AD3209 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\95A5270F-EFCE-4029-83C3-1F9562\620FFC54-E2D7-435C-803A-8DB9EF -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\9CA6FDD7-961C-4ED6-BA54-0AA6A6\3321B411-FDD0-4BE1-821C-6A3F7C -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\A4495345-A1AC-4CF8-85C9-E9A261\44184068-6F26-4249-B78D-6FB40B -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\A6747917-1E68-47C1-AE9B-D31FDD\CB5700BC-903E-449F-8FB8-46738D -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\AAD2AF89-440E-4426-84E6-C9C0B1\E63B445F-8F29-41C1-8045-B52EA8 -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\B3D5AE42-E2D2-4C6F-B93B-5DAE73\561D9582-F728-4D90-992B-C4CFCF -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\BD1EBF6E-2EC7-4F0D-8FB5-31A0F7\F04F430C-927C-4A3D-BBF6-77EC3B -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\C33CB264-25DE-43C7-B272-8E2E93\E1B62E9C-B7A6-48DB-8FD4-2E0555 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\C59AEED6-093A-4073-ABCA-BB9927\E88485E3-C647-4B04-9F7C-E2F5FC -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\C741DD44-DECA-4A19-A062-D3024C\80D10060-84B9-4555-A40A-D152F8 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\CB669CFE-D2BC-4962-A150-959F66\F234C226-22D6-458E-97AD-8CA246 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\CC63FEEB-D806-41F0-91DF-AF5DC4\3C1D8FA3-7201-41BA-89AF-8BCDF3 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\D6748854-6D45-4998-91C4-3EB98D\C06A72CC-19DB-4CD8-A65B-609262 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\D6748854-6D45-4998-91C4-3EB98D\DC191526-C3B8-479B-979A-FE5569 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\DDB66D23-ED93-4D21-AF45-B06751\45621A62-9832-4325-A1C0-49F5F9 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\DF7C0D70-8B36-4391-B6A0-4E981B\53642ECE-A560-451F-8B19-C5A01E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E4EFAF65-2F76-40F1-81B4-D51847\6CFD951E-43EF-43FC-B8BE-E074B8 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E7BD1BF5-D58F-421A-AE0D-0E6E51\92BB9A2E-5E63-4D75-B9D1-8AA3BF -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E9AEA248-580C-4CDF-9FB4-8525E1\15DCD788-7860-4D3F-B98B-310636 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E9AEA248-580C-4CDF-9FB4-8525E1\D7F4B9BA-5E6D-456F-866F-54D145 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E9AEA248-580C-4CDF-9FB4-8525E1\EDBEF209-F3F8-4139-B293-E4A402 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\E9AEA248-580C-4CDF-9FB4-8525E1\FB21722C-3CC4-4455-B988-767B95 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\EA02F719-BF10-4586-879E-FF42C9\29B8B78A-7062-4CBF-95BB-D8002A -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\EA205AF5-8F62-4138-9FE1-C92F70\DC7105E5-6753-482B-95F2-A91324 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\EF3D2AF0-C20F-4876-8889-94CFFD\D6BD3A8C-4CC0-45ED-8B88-011C5D -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\F228FCDA-DD98-40EB-BE25-188466\F2642856-7F44-4889-9E08-49F3C4 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\F85C23F6-A026-4F77-B4DE-A02708\FC723AA4-EF04-4C44-BE26-D7C55E -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\F877E65B-702A-4FEF-A250-F3348B\A9541358-8F2D-440C-8E9F-8BF9B6 -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Program Files\Windows Media Player\wmplayer.exe.tmp -> TrojanDropper.VB.cd -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP108\A0002333.exe -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP110\A0002342.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP111\A0002359.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP114\A0002415.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP116\A0002455.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP119\A0002544.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP120\A0002565.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP121\A0002567.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP124\A0002598.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP124\A0002651.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP125\A0002662.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP126\A0002681.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP127\A0002704.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP128\A0002725.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP129\A0002728.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP130\A0002754.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP132\A0002799.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP133\A0002814.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP139\A0002850.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP140\A0002919.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP141\A0002930.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP142\A0002951.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP144\A0002957.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP145\A0002977.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP147\A0003040.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003057.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003058.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003072.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003075.dll -> Spyware.NoName -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003086.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP148\A0003093.exe -> TrojanDropper.Inflator.b -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP149\A0003108.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP149\A0003110.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP149\A0003112.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003117.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003118.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003120.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003413.exe -> TrojanDropper.Inflator.b -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003467.dll -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003470.dll -> Spyware.BiSpy.t -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003471.exe -> Trojan.KeyHost.e -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003472.exe -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003473.exe -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003474.dll -> Spyware.BiSpy.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003476.exe -> Spyware.Ebates.a -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003477.DLL -> Trojan.KeyHost.e -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003478.exe -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003479.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003480.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP150\A0003481.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003516.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003518.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003528.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003532.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003540.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003548.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\A0003554.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\snapshot\MFEX-5.DAT -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{B5900582-1901-4F7E-BAFE-8FEB08721D95}\RP151\snapshot\MFEX-94.DAT -> Trojan.Imiserv.c -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gamebar.dll -> Spyware.MegaSearch.b -> Cleaned with backup
C:\WINDOWS\enhtb.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\WINDOWS\enhuninstall.exe -> Spyware.NoName -> Cleaned with backup
C:\WINDOWS\svcproc.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\WINDOWS\SYSTEM32\DrPMon.dll -> Trojan.Agent.db -> Cleaned with backup
C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\WINDOWS\xoetgjomfes.exe -> Spyware.BetterInternet -> Cleaned with backup
::Report End
Thanks Again!!!