Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PS Guard. HiJackThis log included


  • Please log in to reply

#1
p3ps1

p3ps1

    New Member

  • Member
  • Pip
  • 2 posts
Hello, this is my first time on geekstogo.com and the trouble I'm having is getting rid of PS Guard... although I "uninstalled" it from my Add/Remove programs list, it's come up again and as a result, there is an annoying desktop wallpaper that says "Warning! Your computer might be infected with adware or spyware...etc"

I've been to some other forums and have run all sorts of spyware removers but nothing (so far) seems to have worked!

Below is my HiJackThis log...

Thank you in advance!

Logfile of HijackThis v1.99.1
Scan saved at 10:17:28 PM, on 25/07/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\s3hotkey.exe
C:\WINDOWS\System32\S3Tray2.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Pxfausr\Tfcknz.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\addmi32.exe
C:\WINDOWS\System32\intell32.exe
C:\WINDOWS\System32\combo.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Apoint2K\Apntex.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\crpj32.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Documents and Settings\Janice Kim\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.riumlkpss...rfMarmDOGo.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rmwqd.dll/sp.html#63796
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rmwqd.dll/sp.html#63796
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {97ADA2E0-5C10-1C68-6762-039DC911BD1A} - C:\WINDOWS\system32\crnq32.dll
O2 - BHO: Class - {F6C7147A-098C-1D1F-630B-149EFA0CF231} - C:\WINDOWS\system32\crxb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [S3Hotkey] s3hotkey.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe /Type 20
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Kudkwbdk] C:\Program Files\Pxfausr\Tfcknz.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [GreatPileHoleBias] C:\Documents and Settings\All Users\Application Data\Bleh Window Great Pile\16 dash.exe
O4 - HKLM\..\Run: [addmi32.exe] C:\WINDOWS\system32\addmi32.exe
O4 - HKLM\..\Run: [NAVNet] "C:\DOCUME~1\JANICE~1\LOCALS~1\Temp\12.tmp" /m
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [combo.exe] combo.exe
O4 - HKLM\..\RunServices: [Microsoft Security Update] ne.exe
O4 - HKCU\..\Run: [Nurb Lite] C:\DOCUME~1\JANICE~1\APPLIC~1\LISTTI~1\data admin.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [a055RTM2V] iyufile.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {82AC6359-97F1-462A-B513-2FE86F08DCCF} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {82AC6359-97F1-462A-B513-2FE86F08DCCF} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {85AF9A98-3423-45E4-8BAD-85645F16AC31} (P3 Bugs VoD Loader Class) - http://player.bugs.c.../mv/p3bvset.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) - http://player.bugs.c...der20041018.cab
O16 - DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} (FotkiUploader Control) - http://images.fotki....tkiUploader.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crpj32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GBPoll - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
  • 0

Advertisements


#2
p3ps1

p3ps1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
sorry, I forgot to add in my ewido security logfile...

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:11:43 PM, 25/07/2005
+ Report-Checksum: F03536D4

+ Scan result:

HKLM\SOFTWARE\Avenue Media -> Spyware.InternetOptimizer : Error during cleaning
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Spyware.InternetOptimizer : Error during cleaning
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Spyware.InternetOptimizer : Error during cleaning
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper\cf1 -> Spyware.InternetOptimizer : Error during cleaning
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E15C1770-8B06-C7F0-92C3-8514CE8ED8C1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{52CACFDF-9170-46A9-AE2E-E594D324C72A} -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CLSID -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CurVer -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\ISTbar -> Spyware.ISTBar : Error during cleaning
HKLM\SOFTWARE\ISTbar\Historyfiles -> Spyware.ISTBar : Error during cleaning
HKLM\SOFTWARE\ISTbar\Historystring -> Spyware.ISTBar : Error during cleaning
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winds_24 -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2681017343-3134616843-1333191943-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
C:\Documents and Settings\Janice Kim\Cookies\janice kim@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\16.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\dd.exe -> Trojan.TopAntiSpyware : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\f2s6bF.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\jhnf.exe -> TrojanDropper.Joiner.aj : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\temp.fr1E98\atl.dll -> Trojan.Pakes : Cleaned with backup
C:\Documents and Settings\Janice Kim\Local Settings\Temp\temp.fr68C4\atl.dll -> Trojan.Pakes : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\A6FZVS6Z\iesetup[1].exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ZHKA39B2\icp[1].exe -> TrojanDownloader.IstBar.is : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\01025BE5-19B3-4AF1-8608-025252\7CBB8F4C-59A3-462E-948F-7BFCC7 -> TrojanDownloader.Apropo.ab : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\02B3AC10-FDD1-44A2-9592-664558\E50C95DF-82E8-47CB-8CC6-DE95BE -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\06188909-F329-42F5-B081-461F01\11879C2A-C76B-4D98-9F4B-C788B5 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\06188909-F329-42F5-B081-461F01\1518BCC5-0E90-4B02-8F89-04D73F -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\06188909-F329-42F5-B081-461F01\5823760B-EC8D-4AE1-A009-8ECF99 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\06188909-F329-42F5-B081-461F01\63B11030-2F1E-4727-8C45-3CA155 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\06188909-F329-42F5-B081-461F01\7F19DED1-243A-4F07-8FEE-435E19 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0BF970CE-9CD2-48BE-A968-7E05E9\3CAC0992-7FAB-4B2F-B16C-0C4077 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0BF970CE-9CD2-48BE-A968-7E05E9\9C3ED990-0F1C-4475-AE2B-A765E8 -> Spyware.IBIS : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0BF970CE-9CD2-48BE-A968-7E05E9\A3299EDA-B89C-456A-BAC7-42D94C -> Spyware.IBIS : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0DAEB284-E069-4165-A83A-BA8179\167D2366-8D09-48B0-B36B-299B87 -> TrojanDownloader.Apropo.ab : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0DAEB284-E069-4165-A83A-BA8179\22639E00-58F7-40A9-8CA7-CA4800 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0DAEB284-E069-4165-A83A-BA8179\5D1C6605-57F9-44CF-905F-379310 -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0DAEB284-E069-4165-A83A-BA8179\95D61C90-F68B-4D5F-BC29-06D90E -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\222C8351-B771-4377-9395-E40EE3\F14D293B-2D52-4703-BA0A-AD2D51 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\2A166459-94D8-4FB7-8991-93D8B4\39BD0E5F-6C02-467B-8B43-F5FCD7 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\2BCDA6A2-CAC1-45E4-AA07-E22D49\0313F6DF-EB3A-4B24-ABBF-76077A -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\37CB33A1-AF7C-4F00-AEEF-40DD55\DA1B406A-9ECE-4133-8838-94FEF6 -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\37CB33A1-AF7C-4F00-AEEF-40DD55\DCBB591C-ECE1-43C4-B35E-1C034F -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\37CB33A1-AF7C-4F00-AEEF-40DD55\E1E9BCE5-CF56-4432-BE0C-FC9ECE -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\37CB33A1-AF7C-4F00-AEEF-40DD55\E917D520-58A6-4B1C-8F23-B1BCBC -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\55A28EF8-9AB6-41B0-B7D8-441841\E63FEF19-2B9D-4707-A459-D7BD80 -> Adware.SAHA : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\66342850-B01E-4634-9654-E8CACA\9BA41771-8357-48C9-B50B-EFDF75/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\6CE8B645-A25E-48B3-B730-AAF6E6\7D0BA751-81DB-4A76-B1F4-A84527/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\6EE16810-6CB8-4938-8147-784954\14DDAE8B-E2AD-43C3-BE3C-531524 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\6EE16810-6CB8-4938-8147-784954\7D65C0A3-28D3-4992-BA8B-5AB172 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\6EE16810-6CB8-4938-8147-784954\89C4F390-BD76-4E20-99F5-8A17C6 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\74DD27BE-13A6-474E-A063-CD136D\C99B07FD-CD84-480E-8DB0-CBA093/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7EA0E92-CF7C-4234-B511-C2760D\41AF41EB-1B1A-4B49-9731-07DB3F -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7EA0E92-CF7C-4234-B511-C2760D\67F66988-E83C-492A-A636-FCFA44 -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\A7EA0E92-CF7C-4234-B511-C2760D\70C94E84-8C04-414B-AC5F-B596AC -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B4AAC9D5-EFBD-455B-9C63-049289\080AF56E-4686-4D3A-896F-600882 -> TrojanDownloader.Wintool.f : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B4AAC9D5-EFBD-455B-9C63-049289\6AE0E1A0-932C-4DDF-9522-3E7090 -> Spyware.Wintol : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B4AAC9D5-EFBD-455B-9C63-049289\C5F75D04-0589-4460-8E3F-02CA9F -> Spyware.Wintools : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\BC71BD0B-A2DF-4681-9E8C-1B7CA6\120B7779-4FB6-46CA-AA20-34247E -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\BC71BD0B-A2DF-4681-9E8C-1B7CA6\5D33CD10-134C-4C83-8A59-22C9F8 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C62B19CC-58DD-4D82-B43B-5EDEB2\7AFD5A50-68DD-489C-B9FE-B0CA50 -> Spyware.180Solutions.b : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\DC916C19-E2BA-40D2-B464-649EE6\631D5FAB-7AAB-415E-A38D-577616 -> Spyware.UCmore : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F7CFCD13-939B-4CC1-B730-566C60\18FC2B14-0A9E-4B4F-B60B-C614A5 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F7CFCD13-939B-4CC1-B730-566C60\AA025D0C-7D1D-4607-817B-E49004 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F7CFCD13-939B-4CC1-B730-566C60\E2FB7484-0C50-4D4F-BA2B-FBD14B -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Pxfausr\Tfcknz.exe -> Trojan.Small.cy : Cleaned with backup
C:\WINDOWS\addav.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apinl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atlaf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlby.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlnw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\buldj.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\cdplayer.ini:ivkwm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crjq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crlj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3lp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3xy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\IE4 Error Log.txt:wsnydf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iejr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipam32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipkl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javaap.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javawf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\lzohv.txt:wgyjtn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfccd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:pgjonp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netkk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netlm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntoc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBC.INI:bcpevp -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\rmwqd.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\sdkap32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkcr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkej.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkmg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sdkyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\setuplog.txt:brfawl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\smscfg.ini:lafqyt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\smscfg.ini:zmpcp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system.ini:ldabjn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system.ini:ryuyri -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32:ioaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addat.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\adddn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\addej32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addmi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crnq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crpj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crxb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3ai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ha32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3uh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3yq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\guninst.exe -> TrojanDropper.Agent.hy : Cleaned with backup
C:\WINDOWS\system32\hookdump.exe -> Trojan.TopAntiSpyware : Cleaned with backup
C:\WINDOWS\system32\ienz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\intell32.exe -> Trojan.Small.ev : Cleaned with backup
C:\WINDOWS\system32\ipfb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iptz.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\javaxv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mssf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netdv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netgl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netpw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\netrx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ntcs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntkb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntrl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\oleext.dll -> TrojanDownloader.Agent.ns : Cleaned with backup
C:\WINDOWS\system32\sdkik.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sysah.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sysjh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sysru32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\winpq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\zqtoo.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\vbaddin.ini:jymlls -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wbibu.txt:ngoavn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wfmug.txt:fhgnyy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\yxngs.txt:agidam -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:azqqav -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:bkoxyv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:cdtttp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:cowrb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:fthly -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:gyybrz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:iyflyl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:jrwswl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:jwmju -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:kxulsp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:neogbo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:qumhhj -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:sxypee -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\_default.pif:ulhdsg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:vedynr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:yzrolj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:zwcfye -> Trojan.Agent.bi : Cleaned with backup


::Report End
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP