Logfile of HijackThis v1.99.1
Scan saved at 8:00:03 PM, on 28/07/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO 2005 version 7\monitor.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\Program Files\Belkin\Bluetooth Software\BTStackServer.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Wayne Esmonde\My Documents\My Programs\SPYWARE\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKCU\..\Run: [Advanced Uninstaller PRO Installation Monitor] "C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO 2005 version 7\monitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Wayne Esmonde\Desktop\HijackThis.exe /startupscan
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apphg.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:20:54 PM, 28/07/2005
+ Report-Checksum: 1A29EA2D
+ Scan result:
C:\Documents and Settings\Wayne Esmonde\My Documents\My Programs\INTERNET\Download Accelerator Plus v7.2.0.0. & Crack.rar/crack\DAP.exe -> Spyware.Dap : Ignored
C:\Program Files\DAP\DAP.exe -> Spyware.Dap : Ignored
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B595A235-53A2-27D5-EFF6-D0208801D071} -> Spyware.CoolWebSearch : Cleaned with backup
C:\!Submit\d3iv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\!Submit\msbg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\!Submit\msdh.exe -> Trojan.Agent.bi : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Wayne Esmonde\Application Data\Mozilla\Firefox\Profiles\5b0pgsfz.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Wayne Esmonde\Application Data\Mozilla\Firefox\Profiles\5b0pgsfz.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Wayne Esmonde\Application Data\Mozilla\Firefox\Profiles\5b0pgsfz.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Wayne Esmonde\Application Data\Mozilla\Firefox\Profiles\5b0pgsfz.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Wayne Esmonde\Application Data\Mozilla\Firefox\Profiles\5b0pgsfz.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Wayne Esmonde\Desktop\SPYWARE\backups\backup-20050728-150108-764.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\Wayne Esmonde\My Documents\My Programs\Norton\Norton KeyGens\Norton Internet Security 2005 Key Generator.exe -> TrojanDropper.Delf.fd : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017171.ini:ohney -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017172.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017175.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017189.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017190.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017191.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017192.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017197.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017198.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017199.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017225.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017226.ini:ohney -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017227.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017228.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP26\A0017229.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017243.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:kvupx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017245.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017246.prx:vzvgcz -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017253.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:fbxeqr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:fzcqrb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:kvupx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017255.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017256.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017262.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{0AFC2C9D-5FBA-45E7-AA81-E18DE2A2719D}\RP27\A0017263.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Ascd_tmp.ini:cpnkhq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\clock.avi:fjycdc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\clock.avi:nyslpz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:smtnxe -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:ohney -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:dvmexd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iis6.log:vvfjz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iis6.log:vvfjzg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcqn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msdfmap.ini:umxly -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\num41.jbd:eulft -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ocgen.log:ufkxrx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:ngdcli -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:qrmdh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:tfrgi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS.OLD:rjdoh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\River Sumida.bmp:bspwd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sysou.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32:nnaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieru32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxi32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sysxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\win.ini:lyswgm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\WMSysPrx.prx:vzvgcz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Zapotec.bmp:khjafj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:fbxeqr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:fzcqrb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:ivgfxb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:kvupx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_default.pif:miuwd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:octvph -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_default.pif:omobu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:qdwzvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:vbjive -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:xcdmb -> TrojanDownloader.Agent.bc : Cleaned with backup
F:\System Volume Information\_restore{0BBBC1F4-CE1C-4780-AE93-48C23DD2F8B7}\RP19\A0009139.exe -> Dialer.Generic : Cleaned with backup
F:\System Volume Information\_restore{0BBBC1F4-CE1C-4780-AE93-48C23DD2F8B7}\RP20\A0010188.exe -> Worm.VB.an : Cleaned with backup
::Report End