thank you for your help, as far as i can tell the AntivirusGold virus is gone.
here is the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 10:53:35 PM, on 7/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.netcenter.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.top20results.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 213.219.251.80 go.com
O1 - Hosts: 213.219.251.80 www.go.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AzEntretien Class - {0d2def3a-f4f1-42ec-ac4f-132e7ba6e292} - %SystemRoot%\azentretien.dll (file missing)
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINDOWS\System32\azesearch4.ocx (file missing)
O3 - Toolbar: AZE Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINDOWS\System32\azesearch4.ocx (file missing)
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [xmbahut] C:\WINDOWS\xmbahut.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [qgui9vrv] C:\WINDOWS\System32\qgui9vrv.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\humh.exe reg_run
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [AntivirusGold] C:\Program Files\AntivirusGold\AntivirusGold.exe /h
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: rctr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: eWare Startup.lnk = C:\Program Files\eWare\iWareStart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: Win32 Classes -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120265171473O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} -
http://www.azebar.co...l/azesearch.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
here is the eWido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:47:56 AM, 7/11/2005
+ Report-Checksum: 79F26BA2
+ Scan result:
C:\WINDOWS\SYSTEM32\ncun.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\WINDOWS\SYSTEM32\ivni.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\undo\backup.cab/C:\WINDOWS\Start Menu\Programs\StartUp\rctr.exe -> TrojanDownloader.Qoologic.u : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\Desktop\cmb_260918.vxd -> Heuristic.Win32.Dialer : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\Application Data\lmrc.vxd -> Spyware.PurityScan : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\P2P Networking\p2p networking2.vxd -> Spyware.P2PNetworking : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\javexulm.vxd -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/exdl.exe -> Adware.eXact : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/exul.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/javexulm.vxd -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/bbchk.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/msexreg.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/instsrv.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\SYSTEM32\iasad.dll -> Spyware.AzeSearch : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\SYSTEM32\QaBar.dll -> Spyware.Hijacker.Generic : Error during cleaning
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rctr.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Documents and Settings\Default\Application Data\hpbt.exe -> Spyware.PurityScan : Cleaned with backup
:mozilla.5:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Gator : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP11\A0000897.exe -> Spyware.Pacer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001394.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001400.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001426.ocx -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001428.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001447.exe -> Spyware.WeirWeb : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001475.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001476.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001498.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001504.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001505.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001506.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001507.exe -> Adware.Saha : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001509.dll -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001516.ocx -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001555.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001568.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001569.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001843.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001844.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001848.exe -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001849.exe -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001852.DLL -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001855.exe -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001856.dll -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001857.dll -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001858.exe -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001875.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001876.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001877.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001879.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001880.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001885.exe -> Spyware.DelphinMediaViewer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001886.exe -> Spyware.Pacer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002212.exe -> TrojanDownloader.Apropo.ac : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002213.exe -> TrojanDownloader.Agent.ed : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002216.dll -> Trojan.TalkStocks.a : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002218.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002219.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002220.exe -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002221.DLL -> Spyware.P2PNetworking : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002222.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002223.dll -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002224.ocx -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002225.dll -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002226.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002227.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002228.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002229.dll -> Trojan.Goldid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002230.dll -> Trojan.Goldid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002231.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002232.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002233.dll -> TrojanDropper.Noname.a : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002234.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002235.exe -> Trojan.Golid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002236.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002237.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002238.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002239.exe -> TrojanDownloader.Small.cg : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002240.dll -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002241.exe -> Spyware.BookedSpace : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002242.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002243.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002244.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002245.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002246.dll -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002247.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002250.exe -> Adware.Saha : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002251.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002252.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002253.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002254.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002258.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002259.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002260.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002261.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002320.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
::Report End
and here is the smitRem log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:47:56 AM, 7/11/2005
+ Report-Checksum: 79F26BA2
+ Scan result:
C:\WINDOWS\SYSTEM32\ncun.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\WINDOWS\SYSTEM32\ivni.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\undo\backup.cab/C:\WINDOWS\Start Menu\Programs\StartUp\rctr.exe -> TrojanDownloader.Qoologic.u : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\Desktop\cmb_260918.vxd -> Heuristic.Win32.Dialer : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\Application Data\lmrc.vxd -> Spyware.PurityScan : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\P2P Networking\p2p networking2.vxd -> Spyware.P2PNetworking : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\javexulm.vxd -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/exdl.exe -> Adware.eXact : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/exul.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/javexulm.vxd -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/bbchk.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/msexreg.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\system\netut80ex.vxd/C:/WINDOWS/SYSTEM/instsrv.exe -> Spyware.BargainBuddy : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\SYSTEM32\iasad.dll -> Spyware.AzeSearch : Error during cleaning
C:\undo\backup.cab/C:\WINDOWS\SYSTEM32\QaBar.dll -> Spyware.Hijacker.Generic : Error during cleaning
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rctr.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Documents and Settings\Default\Application Data\hpbt.exe -> Spyware.PurityScan : Cleaned with backup
:mozilla.5:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Gator : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\manso003\7w2n83jr.slt\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP11\A0000897.exe -> Spyware.Pacer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001394.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001400.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001426.ocx -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001428.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001447.exe -> Spyware.WeirWeb : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001475.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001476.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001498.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001504.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001505.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001506.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001507.exe -> Adware.Saha : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001509.dll -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001516.ocx -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP17\A0001555.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001568.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001569.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001843.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001844.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001848.exe -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001849.exe -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001852.DLL -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001855.exe -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001856.dll -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001857.dll -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001858.exe -> Spyware.IBIS : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001875.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001876.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001877.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001879.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001880.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001885.exe -> Spyware.DelphinMediaViewer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP18\A0001886.exe -> Spyware.Pacer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002212.exe -> TrojanDownloader.Apropo.ac : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002213.exe -> TrojanDownloader.Agent.ed : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002216.dll -> Trojan.TalkStocks.a : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002218.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002219.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002220.exe -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002221.DLL -> Spyware.P2PNetworking : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002222.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002223.dll -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002224.ocx -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002225.dll -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002226.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002227.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002228.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002229.dll -> Trojan.Goldid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002230.dll -> Trojan.Goldid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002231.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002232.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002233.dll -> TrojanDropper.Noname.a : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002234.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002235.exe -> Trojan.Golid : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002236.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002237.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002238.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002239.exe -> TrojanDownloader.Small.cg : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002240.dll -> Spyware.FindSpy : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002241.exe -> Spyware.BookedSpace : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002242.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002243.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002244.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002245.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002246.dll -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002247.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002250.exe -> Adware.Saha : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002251.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002252.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002253.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002254.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002258.dll -> Spyware.AzSearch : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002259.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002260.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002261.dll -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{07B72A25-53D0-48D5-ADB8-096C3371FE4F}\RP22\A0002320.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
::Report End
once again thank you very much.