Sorry for taking so long to follow through, I had some unexpected work duties.
Ewido Log:
+ Created on: 3:09:49 PM, 8/3/2005
+ Report-Checksum: 69071BDD
+ Scan result:
:mozilla.6:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.12:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.13:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.14:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.17:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.19:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.97:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.110:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.111:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.112:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.113:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.114:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.115:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.119:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.120:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.125:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.134:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.135:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.136:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.137:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.138:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.139:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.140:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.153:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.154:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.155:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.156:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.157:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.159:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.160:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.161:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.162:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.163:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.164:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.184:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.185:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.186:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.211:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\bcrzkb74.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\John\Cookies\john@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\John\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\dmfcppmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\fckkmpjc.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\ficcppmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\jepfmpmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\kokndhld.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\lmlhbpjd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\mjhlhomd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\mpgnjngd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\nojkoknd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\pifbfcod.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\pmpcomod.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\John\Local Settings\Temp\snuninst.exe -> TrojanSpy.Bancos.ds : Cleaned with backup
C:\DRIVERS\VIDEO\ONBOARD\IGFXTRAY.EXE -> TrojanDropper.Paradrop.a : Cleaned with backup
C:\I386\igfxtray.exe -> TrojanDropper.Paradrop.a : Cleaned with backup
C:\RECYCLER\NPROTECT\00018125.exe -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00018127.dll -> Adware.SAHA : Cleaned with backup
C:\RECYCLER\NPROTECT\00018246.exe -> Adware.SAHA : Cleaned with backup
C:\RECYCLER\NPROTECT\00018247.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP101\A0002684.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP101\A0002902.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP102\A0002912.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP103\A0002988.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP103\A0003033.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP103\A0003110.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP104\A0003126.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP104\A0003235.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP64\A0001757.exe -> TrojanDownloader.Small.aaq : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP64\A0001778.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP64\A0001785.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP64\A0001786.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP64\A0001831.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP65\A0001851.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP65\A0001864.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP66\A0001886.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001922.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001923.exe -> TrojanDownloader.Agent.qq : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001924.exe -> TrojanDownloader.Agent.qq : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001926.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001928.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001931.DLL -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001934.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP69\A0001981.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP70\A0002022.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP70\A0002024.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP79\A0002055.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP89\A0002108.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP90\A0002116.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP90\A0002120.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP90\A0002127.exe -> TrojanDownloader.Agent.qu : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP94\A0002144.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP96\A0002264.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP99\A0002364.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP99\A0002446.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\jcnpbchao.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\lqezwwa.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\nph008cp.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\SYSTEM\Loader.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\WINDOWS\SYSTEM32\bwvbdt.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\csvgbd.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\igfxtray.exe -> TrojanDropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\jjmzmmk.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\lgvi.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\mlvgxiz.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsd2.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\pqyiwef.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\prkbvnz.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\qbnpj.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\qqpzcmj.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\redtrsha.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\SYSTEM32\richup.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\SYSTEM32\td9tnkft.exe -> Adware.Saha : Cleaned with backup
C:\WINDOWS\SYSTEM32\tvqhv.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\umch.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\uvifrqq.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\wrefxtb.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\SYSTEM32\xgppkg.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
::Report End
Hijack This Log:
Logfile of HijackThis v1.99.1
Scan saved at 3:39:10 PM, on 8/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Lavasoft\Hijack This\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://webmail.pacif...m/src/login.phpR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121217557698O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{D4FADFC3-586A-4B33-80C7-18205B92D2F5}: NameServer = 209.244.0.3 209.244.0.4
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Thanks again.