Thanks again for your help. The scans found alot of infections!
Ewido results:---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:30:57 PM, 7/6/2005
+ Report-Checksum: BA8443E4
+ Scan result:
HKU\S-1-5-21-1005918099-2721185907-3207641511-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{0656A137-B161-CADD-9777-E37A75727E78} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1005918099-2721185907-3207641511-1006\Software\WareOut -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1005918099-2721185907-3207641511-1006\Software\WareOut\FirstRun -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1005918099-2721185907-3207641511-1006\Software\WareOut\Options -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1005918099-2721185907-3207641511-1006\Software\WareOut\Registration -> TrojanDownloader.Wareout : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP10\A0000720.exe -> Spyware.HelpExpress : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003349.exe -> Heuristic.Win32.Morphine-Crypted : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003351.dll -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003412.exe -> Worm.Prex.d : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003413.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003448.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003449.exe -> Spyware.HelpExpress : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003450.exe -> TrojanDownloader.Dyfuca.dp : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003451.exe -> TrojanDownloader.Dyfuca.de : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003460.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003461.exe -> TrojanDownloader.Dyfuca.dp : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003462.exe -> TrojanDownloader.Dyfuca.de : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003463.exe -> Worm.Prex.d : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP17\A0003467.exe -> TrojanDownloader.Wintool.f : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP25\A0005130.DLL -> Spyware.P2PNetworking : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP25\A0005135.exe -> Spyware.P2PNetworking : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP29\A0005345.dll -> TrojanDownloader.Dyfuca.dt : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP31\A0005415.exe -> TrojanDropper.Small.wv : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0005538.dll -> TrojanProxy.Small.bk : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0005546.exe -> Trojan.Agent.dv : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0006552.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0006561.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0006563.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0007563.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP32\A0007604.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007608.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007620.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007629.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007633.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007634.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007642.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007646.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007650.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007654.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007660.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007663.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007671.dll -> Spyware.Visiter : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007672.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007674.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007683.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007685.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007690.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007695.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007700.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007737.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007742.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007749.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007752.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007757.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007762.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP33\A0007767.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008148.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008176.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008179.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008184.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008189.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008190.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008191.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008194.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008199.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008204.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008209.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008214.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0008220.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0009215.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0010215.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0011214.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0011219.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0011224.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0011229.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0012224.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0013224.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0014224.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0015224.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP34\A0015269.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015280.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015285.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015287.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015293.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015294.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP35\A0015299.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP37\A0015321.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP37\A0015341.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP53\A0015733.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP54\A0015797.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP54\A0015799.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP54\A0015807.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015866.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015867.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015935.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015946.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015947.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP56\A0015955.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP6\A0000137.exe -> TrojanDropper.Small.ue : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP69\A0017957.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP69\A0018059.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP7\A0000426.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP7\A0000488.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018079.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018099.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018100.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018101.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018102.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018108.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018123.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018129.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018137.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018142.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018147.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018173.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP70\A0018179.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP71\A0018188.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP71\A0018195.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP71\A0018202.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP71\A0018207.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018221.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018296.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018301.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018306.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018311.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018316.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018321.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP72\A0018322.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP73\A0018346.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP73\A0018351.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP73\A0018356.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP74\A0018407.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP76\A0020522.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP76\A0020534.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP76\A0020540.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP77\A0020554.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP77\A0020555.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP77\A0020556.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP78\A0020562.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP78\A0022570.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP78\A0022580.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP78\A0022581.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP78\A0022597.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP79\A0022621.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP79\A0022624.exe -> Spyware.Msnagent : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP79\A0022645.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP79\A0022646.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP80\A0022654.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP80\A0022655.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP80\A0022656.exe -> Spyware.Msnagent : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP80\A0022657.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0022676.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0022677.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0022678.exe -> Spyware.Msnagent : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0022679.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0022686.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024705.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024708.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024713.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024717.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024721.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024728.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024729.exe -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024730.exe -> Spyware.Msnagent : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024731.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0024900.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\System Volume Information\_restore{E79AE979-DA07-45B0-A865-BFCAD8292C86}\RP81\A0025034.exe -> Trojan.DNSChanger.q : Cleaned with backup
C:\WINDOWS\system32\drv2cltr.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\WINDOWS\system32\ntfsnlpa.exe -> Spyware.Msnagent : Cleaned with backup
::Report End
ActiveScan: The scan came up clean. No viruses found.New HijackThis log:Logfile of HijackThis v1.99.1
Scan saved at 10:44:55 PM, on 7/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\AntiVirPersonal\AVGUARD.EXE
C:\Program Files\AntiVirPersonal\AVWUPSRV.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\AntiVirPersonal\AVGNT.EXE
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack This\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://toshibadirect.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocpa.dll/asst.htm
R3 - URLSearchHook: (no name) - {0EC1ECF5-1F3A-00B9-FAF6-E9F4809EF3AD} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Internet Explorer Hot Fix - {C95E5924-06C9-49F5-AB4B-5A5DE9DF8D86} - blank (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ToshibaHotKeys] c:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [sload] "C:\WINDOWS\sload.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AntiVirPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [SysSupport] SysEntry.exe
O4 - HKCU\..\Run: [InpriseMon] cmon14.exe
O4 - HKCU\..\Run: [atl_helper] bnui.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {510A645B-D7FC-454D-8FCE-8B3CE6409FD6} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {510A645B-D7FC-454D-8FCE-8B3CE6409FD6} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O15 - Trusted Zone: *.sxload.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1117729510299O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{66CBDBC5-8B2F-4005-9904-C334AF03C458}: NameServer = 69.50.176.198,195.225.176.153
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVirPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AntiVirPersonal\AVWUPSRV.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe