Okies... Here are the reports you asked for.
New HJT Log:Logfile of HijackThis v1.99.1
Scan saved at 2:12:45 PM, on 7/26/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Microsoft Shared\Media Manager\airsvcu.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BellSouth\Application Center\BsnAppCenter.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\StompSoft\Virus X-terminator\bin\ZLH.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\StompSoft\Virus X-terminator\bin\ZANDA.EXE
C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\PCI Audio Applications\Bin\WDM\Full\Mixer.exe
C:\Program Files\StompSoft\Virus X-terminator\Nvc\BIN\NIP.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\StompSoft\Virus X-terminator\bin\NJEEVES.EXE
C:\Program Files\StompSoft\Virus X-terminator\Nvc\BIN\nipsvc.exe
C:\Program Files\StompSoft\Virus X-terminator\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\StompSoft\Virus X-terminator\Nvc\bin\nvcoas.exe
C:\Program Files\StompSoft\Virus X-terminator\Nvc\bin\cclaw.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Support.com\bin\jobcheck.exe
C:\Program Files\Support.com\bin\tgshell.exe
C:\Documents and Settings\Tucker\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bellsouth.net/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/?.home=ytieF2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RUPK - {604B283A-4E26-4504-98E7-72859F949547} - C:\PROGRA~1\HITWAR~1\sypcms.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_5_7_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [BellSouthSyn] C:\Program Files\BellSouth\Application Center\BsnAppCenter.exe /Synchronize
O4 - HKLM\..\Run: [BellSouthScheduler] C:\Program Files\BellSouth\Application Center\BsnAppCenter.exe /Scheduler
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Program Files\StompSoft\Virus X-terminator\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [HitwarePKLite] C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {DECDBEEF-D3AD-B3EF-DE4D-B3EFDEADB3EF} - C:\Program Files\BellSouth\Communications Suite\BstMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.c...nst20040510.cabO16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) -
http://www.icannnews.../ST/ActiveX.ocxO16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} -
http://www.ez-tracks...itial/eztdl.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121821414957O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
http://www.windowsec...scan/axscan.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalci...illama/ampx.cabO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\StompSoft\Virus X-terminator\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Program Files\StompSoft\Virus X-terminator\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Program Files\StompSoft\Virus X-terminator\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\StompSoft\Virus X-terminator\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Program Files\StompSoft\Virus X-terminator\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Volume in drive C is Windows-XP
Volume Serial Number is 400B-1D1D
Directory of C:\WINDOWS\System32
07/13/2005 04:03 PM 401,408 j?vaw.exe
1 File(s) 401,408 bytes
Directory of C:\Documents and Settings\Tucker\Desktop
Bit Defender ReportBitDefender Online Scanner
Scan report generated at: Tue, Jul 26, 2005 - 01:14:17
Scan path: A:\;C:\;D:\;E:\;
Statistics
Time
02:48:31
Files
192549
Folders
5376
Boot Sectors
2
Archives
1207
Packed Files
26071
Results
Identified Viruses
15
Infected Files
48
Suspect Files
1
Warnings
0
Disinfected
0
Deleted Files
49
Engines Info
Virus Definitions
196867
Engine build
AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)
Scan plugins
13
Archive plugins
39
Unpack plugins
4
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Downloads\Install_AIM.exe=>wise0038=>wise0008
Detected with: Adware.Wheaterbug.A
C:\Downloads\Install_AIM.exe=>wise0038=>wise0008
Disinfection failed
C:\Downloads\Install_AIM.exe=>wise0038=>wise0008
Deleted
C:\Downloads\Install_AIM.exe=>wise0038
Update failed
C:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
Detected with: Adware.Wheaterbug.A
C:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
Disinfection failed
C:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
Deleted
C:\Program Files\AIM\Sysfiles\WxBug.EXE
Update failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP404\A0105118.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP404\A0105118.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP404\A0105118.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP418\A0106877.exe
Suspected of: Dropped:Trojan.Downloader.Gen
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP418\A0106877.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP418\A0106877.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP423\A0111355.exe
Infected with: Trojan.Downloader.2669.B
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP423\A0111355.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP423\A0111355.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114867.dll
Infected with: Trojan.Downloader.Qoologic.P
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114867.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114871.exe
Infected with: Trojan.Dloader.OT
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114871.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114871.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114878.dll
Infected with: Trojan.Clicker.Small.EZ
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114878.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP434\A0114878.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP436\A0116112.exe=>wise0008
Infected with: Trojan.Downloader.TSUpdate.J
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP436\A0116112.exe=>wise0008
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP436\A0116112.exe
Update failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116174.exe
Infected with: Trojan.Downloader.TSUpdate.K
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116174.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116175.exe
Infected with: Trojan.Downloader.TSUpdate.J
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116175.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116176.exe
Infected with: Trojan.Downloader.Tsupdate.L
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116176.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116176.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116251.exe
Infected with: Trojan.Downloader.TSUpdate.J
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116251.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116252.exe
Infected with: Trojan.Downloader.Tsupdate.L
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116252.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116252.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116273.exe
Infected with: Trojan.Downloader.TSUpdate.K
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP437\A0116273.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP438\A0116367.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP438\A0116367.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP438\A0116367.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117440.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117440.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117440.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117460.exe
Infected with: Trojan.Downloader.2669.B
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117460.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117460.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117465.exe
Infected with: Trojan.Downloader.2669.B
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117465.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117465.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117466.exe
Infected with: Trojan.Downloader.2669.B
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117466.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP440\A0117466.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119512.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119512.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119512.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119532.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119532.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP441\A0119532.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP442\A0119577.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP442\A0119577.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP442\A0119577.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP443\A0120569.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP443\A0120569.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP443\A0120569.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP444\A0121569.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP444\A0121569.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP444\A0121569.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121601.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121601.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121601.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121618.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121618.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121618.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121645.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121645.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121645.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121646.exe
Infected with: Trojan.Downloader.Adload.A
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121646.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121646.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121658.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121658.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP445\A0121658.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121703.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121703.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121703.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121736.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121736.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121736.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121757.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121757.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0121757.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0122760.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0122760.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0122760.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123763.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123763.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123763.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123783.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123783.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0123783.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124071.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124071.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124075.exe
Infected with: Trojan.Imiserv.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124075.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124075.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124079.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124079.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124079.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124089.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124089.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124104.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124104.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124104.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124111.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124111.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124157.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124157.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124157.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124158.dll
Detected with: Adware.Look2me.AG
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124158.dll
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124158.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124159.dll
Infected with: Trojan.Downloader.Qoologic.P
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124159.dll
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124161.exe
Infected with: Trojan.Dloader.OT
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124161.exe
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124161.exe
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124171.DLL
Infected with: Trojan.Clicker.Small.EZ
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124171.DLL
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124171.DLL
Deleted
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124173.DLL
Infected with: Trojan.Downloader.Braidupdate.D
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124173.DLL
Disinfection failed
C:\System Volume Information\_restore{E9A2D0CD-B510-4BC6-9DB2-7D7F179FC89D}\RP446\A0124173.DLL
Deleted
C:\WINDOWS\trebates.exe
Infected with: Dropped:Application.ProcKill.Jk
C:\WINDOWS\trebates.exe
Disinfection failed
C:\WINDOWS\trebates.exe
Deleted
Panda Virus Scan Report:Incident Status Location
Adware:adware/purityscan No disinfected C:\DOCUMENTS AND SETTINGS\TUCKER\LOCAL SETTINGS\TEMP\!update.exe
Adware:adware/mywebsearch No disinfected C:\DOCUMENTS AND SETTINGS\TUCKER\START MENU\PROGRAMS\STARTUP\MyWebSearch Email Plugin.lnk
Spyware:spyware/bridge No disinfected C:\WINDOWS\SYSTEM32\bridge.txt
Adware:adware/look2me No disinfected C:\WINDOWS\SYSTEM32\guard.tmp
Adware:adware/powersearch No disinfected C:\WINDOWS\SYSTEM32\stlb2.xml
Adware:adware/funweb No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.8-2.inf
Adware:adware/ipinsight No disinfected C:\WINDOWS\INF\alchem.inf
Adware:adware/bookedspace No disinfected C:\WINDOWS\cfgmgr52.ini
Adware:adware/ncase No disinfected C:\WINDOWS\msbb.exe.temp
Adware:adware/twain-tech No disinfected C:\WINDOWS\satmat.ini
Adware:adware/transponder No disinfected C:\DOCUMENTS AND SETTINGS\TUCKER\LOCAL SETTINGS\TEMP\DrTemp
Adware:adware/addestroyer No disinfected C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AdDestroyer
Adware:adware/savenow No disinfected C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\nsv
Adware:adware/virtualbouncer No disinfected C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\VBouncer
Spyware:spyware/betterinet No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TMU
Adware:adware/sidefind No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TSL INSTALLER
Adware:adware/aurora No disinfected HKEY_CURRENT_USER\SOFTWARE\AURORA
Adware:adware/consumeralertsystemNo disinfected HKEY_CURRENT_USER\SOFTWARE\CAS
Adware:adware/sqwire No disinfected HKEY_CURRENT_USER\SOFTWARE\TSL2
Adware:adware/myway No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MYWAYTOOLBAR.SETTINGSPLUGIN
Adware:adware/delfinmedia No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\VIDCTRL
Adware:adware/exactsearch No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ACTIVEX COMPATIBILITY\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}
Spyware:spyware/dyfuca No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\INTERNET OPTIMIZER
Adware:adware/blazefind No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\RUNDLL
Adware:adware/seeqbar No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{34A44FCF-50E3-63A5-A8DA-7835752B9571}
Adware:adware/topmoxie No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{6685509E-B47B-4f47-8E16-9A5F3A62F683}
Adware:Adware/PurityScan No disinfected C:\PC Cleaners\backups\backup-20050725-001454-175.dll
Adware:Adware/Sqwire No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20041126122747.zip[classify.dll]
Adware:Adware/Sqwire No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\20041126122747.zip[tsuninst.exe]
Virus:W32/Sober.V.worm Disinfected C:\WINDOWS\Connection Wizard\Status\packed1.sbr
Adware:Adware/FunWeb No disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.8-2.inf
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\alchem.inf
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\conscorr.inf
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\polall1r.inf
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\satmat.inf
Adware:Adware/IPInsight No disinfected C:\WINDOWS\satmat.ini
Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\guard.tmp
Virus:Trj/Qoologic.G Disinfected C:\WINDOWS\system32\pukvv.dat
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\Shex.exe
I can't believe that I've still finding stuff on my system... Look forward to getting the set of instructions. BTW is there any way to remove the restore files from my system? I just wonder if those restore points could be reinfecting my system.
Edited by LdyLuv, 26 July 2005 - 12:27 PM.