Sorry for the delay, I didnt recieve e-mail notification that you had posted
New HJT log :Logfile of HijackThis v1.99.1
Scan saved at 2:59:15 PM, on 02/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\StealthBot\StealthBot v2.6R3.exe
C:\Program Files\mIRC\mirc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Coffee\Desktop\hjt\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [delfile] C:\delfiles.cmd
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E8811D37-672A-41EF-A896-E63DAA4C99FA}: NameServer = 206.47.244.13 206.47.244.60
O20 - Winlogon Notify: WB - C:\PROGRA~1\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
EWIDO REPORT---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:31:50 PM, 02/08/2005
+ Report-Checksum: 9451A85E
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{04079851-5845-4dea-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0494D0D9-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\dlIfile -> Spyware.AcidReign : Cleaned with backup
HKLM\SOFTWARE\Classes\dlIfile\shell -> Spyware.AcidReign : Cleaned with backup
HKLM\SOFTWARE\Classes\dlIfile\shell\open -> Spyware.AcidReign : Cleaned with backup
HKLM\SOFTWARE\Classes\dlIfile\shell\open\command -> Spyware.AcidReign : Cleaned with backup
HKLM\SOFTWARE\Classes\ImgConv.clsImgConv -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Classes\ImgConv.clsImgConv\Clsid -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2DDD90D6-F153-4EA7-A324-4B2D83D1027E} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{15E7D23B-736E-46FA-BFFD-CBEC4126BEFD} -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{978C4EC7-60D1-4005-8CE0-D6A7169E36EA} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\saap -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\picsvr -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\saap -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2 -> Spyware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick2\Internet Explorer -> Spyware.SurfSide : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-DD60-0064-6EC2-6E0100000000} -> Spyware.MediaMotor : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000049-8F91-4D9C-9573-F016E7626484} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{16B238D5-80DE-47CE-8F17-B3ECE2C2248D} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{302A3240-4805-4A34-97D7-1645A0B08410} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{79849612-A98F-45B8-95E9-4D13C7B6B35C} -> Spyware.Crazywinnings : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{999A06FF-10EF-4A29-8640-69E99882C26B} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\picsvr -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-448539723-688789844-1708537768-1003\Software\saap -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Coffee\My Documents\My Received Files\netdevil.zip/Edit-server.exe -> Backdoor.NetDevil.15 : Cleaned with backup
C:\Documents and Settings\Coffee\My Documents\My Received Files\netdevil.zip/Net-Devil.exe -> Backdoor.NetDevil.15 : Cleaned with backup
C:\Documents and Settings\Coffee\My Documents\My Received Files\netdevil.zip/Server.exe -> Backdoor.NetDevil.15 : Cleaned with backup
C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP179\A0153124.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP179\A0153125.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP180\A0154143.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP182\A0160206.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0171314.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0172224.exe -> Trojan.Puper.ag : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0172226.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173238.exe -> Trojan.Puper.ag : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173240.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173250.exe -> Trojan.Puper.w : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173264.EXE -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173265.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173266.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP187\A0173278.exe -> Trojan.Puper.ag : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP189\A0173790.exe -> Trojan.Favadd.af : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP189\A0173792.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP189\A0173793.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP191\A0174528.exe -> Trojan.Favadd.af : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP191\A0174530.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP191\A0174531.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP192\A0175019.exe -> Backdoor.ServU-based : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP192\A0175032.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP196\A0179224.exe -> Trojan.Favadd.af : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP196\A0179225.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{C59A5275-B140-4800-8A03-CC71CF5DD183}\RP196\A0179226.exe -> Trojan.Agent.ff : Cleaned with backup
C:\WINDOWS\AuroraHandler.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\m67m.ocx -> Spyware.MediaMotor : Cleaned with backup
C:\WINDOWS\empishq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\gkrdjastcu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\javex80.vxd/C:/WINDOWS/system32/nvms.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\javex80.vxd/C:/Program Files/NaviSearch/bin/nls.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\nsvsvc\nsv.ocx -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\system32\nsvsvc\nsvs.dll -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\system320nsx50 -> Spyware.HotSearchBar : Cleaned with backup
::Report End
PANDA SCANIncident Status Location
Adware:adware/cws.searchmeup No disinfected C:\WINDOWS\SYSTEM32\bose.ico
Spyware:spyware/bargainbuddy No disinfected C:\WINDOWS\SYSTEM32\psis80ex.ax
Adware:adware/keenvalue No disinfected C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho
Spyware:spyware/surfsidekick No disinfected C:\DOCUMENTS AND SETTINGS\COFFEE\APPLICATION DATA\Sskknwrd.dll
Adware:adware/ncase No disinfected C:\WINDOWS\180ax.log
Adware:adware/twain-tech No disinfected C:\WINDOWS\smdat32a.sys
Spyware:spyware/adclicker No disinfected C:\WINDOWS\usta32.ini
Adware:adware/delfinmedia No disinfected C:\WINDOWS\SYSTEM32\nsvsvc
Adware:adware/savenow No disinfected C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\nsv
Spyware:spyware/media-motor No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\MODULEUSAGE\C:/WINDOWS/DOWNLOADED PROGRAM FILES/M67M.OCX
Adware:adware/myway No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MY WAY SPEEDBAR UNINSTALL
Adware:adware/psguard No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSGUARD SPYWARE REMOVER
Adware:adware/wupd No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WEBSPECIALS
Spyware:spyware/betterinet No disinfected HKEY_CURRENT_USER\SOFTWARE\IN3RD
Adware:adware/navipromo No disinfected HKEY_CURRENT_USER\SOFTWARE\MC
Adware:adware/wintools No disinfected HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_TBPSSVC
Spyware:spyware/altnet No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TOPSEARCH.TSLINK
Adware:adware/p2pnetworking No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\P2P NETWORKING
Adware:adware/aurora No disinfected HKEY_CLASSES_ROOT\CLSID\{4AA870AC-8427-42A4-B92E-ECD956197489}
Adware:adware/looksmart No disinfected HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}
Adware:adware/mediatickets No disinfected HKEY_CLASSES_ROOT\TypeLib\{5530D356-0063-41B9-B20D-E9D799E8D907}
Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Coffee\Application Data\tcte.exe
Adware:Adware/PurityScan No disinfected C:\Program Files\aesc\tcte.exe
Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\Downloaded Program Files\m67m.inf
Spyware:Spyware/SafeSurf No disinfected C:\WINDOWS\system32\InstallerV3.exe
Adware:Adware/eZula No disinfected C:\WINDOWS\system32\psis80ex.ax[mscb.dll]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[bb_welcome1.swf]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[bb_welcome.html]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[icon.gif]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[cashback.exe]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[cb.exe]
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\psis80ex.ax[flash.exe]
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\r?gsvr32.exe
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\Shex.exe
Virus:Trj/Downloader.CGX Disinfected C:\WINDOWS\system32\tcte.exe
Adware:Adware/FindWhatever No disinfected C:\WINDOWS\system32\unregister.exe
Virus:W32/Smitfraud.C Disinfected C:\WINDOWS\system32\wininet.old