oh man you're genius I thinhk the virus disappeared, thanks a lot here my new hitjakcs on the other scan log you ask me.
P.D.: I can't run the Panda active scan because i don't see the autoclean box.
Logfile of HijackThis v1.99.1
Scan saved at 4:56:01 PM, on 8/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Samsung\Digimax Viewer 2.0\STImgBrowser.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\drivecheck.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\drivecheck.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Start Menu\Programs\DVD burner\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LyraHD2TrayApp] "C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [drivecheck] C:\WINDOWS\System32\drivecheck.exe
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy (file missing)
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy (file missing)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.sxload.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by105fd.bay10...es/MsnPUpld.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.r...RdxIE601_es.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1117139830937O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:50:56 AM, 8/4/2005
+ Report-Checksum: 231DE9DE
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{38D4D5D0-423E-4220-B6F9-30918C2AE4A4} -> Spyware.BetterInternet : Ignored
HKLM\SOFTWARE\Classes\TypeLib\{8EA362BD-39CB-40F5-9226-73CD40999095} -> Spyware.BetterInternet : Ignored
HKLM\SOFTWARE\Classes\TypeLib\{D88DA98D-48BA-4116-96AB-77C38EAE487F} -> Dialer.Generic : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\Cookies\jeison
[email protected][1].txt -> Spyware.Cookie.Bpath : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\Cookies\jeison
[email protected][1].txt -> Spyware.Cookie.Masterstats : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\SahUpdate\upgrade.exe -> Adware.SAHA : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~100410.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~14512.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~2883.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~326969.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~343258.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~349468.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~3932.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~440553.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~44822.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~479996.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~551611.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~554841.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~557372.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~568920.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~571907.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~57514.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~59162.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~606215.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~609373.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~612256.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~615839.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~616617.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~620349.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~626596.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~630185.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~634109.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~645628.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~662166.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~684452.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~69588.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~711334.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~718833.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~738135.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~856125.tmp -> TrojanDownloader.WinTool : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~910921.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~922256.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~934234.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~935954.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~951886.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~952170.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~952831.tmp -> Spyware.Wintools : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\3IW3ZT0X\secure[1].php -> TrojanDownloader.Psyme.i : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\45UN0PY7\pcs_0006[1].exe -> Spyware.Pacer : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\5ODQCD8O\instalador[1].cab/DownloadHtml.dll -> Spyware.Ruboskizo : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\7N5F750W\mtrslib2[2].js -> TrojanDownloader.Small.ag : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\7N5F750W\mtrslib2[3].js -> TrojanDownloader.Small.ag : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\7N5F750W\sbar[1].exe -> TrojanDownloader.Tibser.c : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\7N5F750W\sbar[2].exe -> TrojanDownloader.Tibser.c : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\AWOYBIJ2\!update-1405[1].0000 -> Spyware.PurityScan : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\J6H0LJ7V\thnall1ac[1].htm -> Adware.BetterInternet : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\AppWrap[1].exe -> TrojanDropper.Small.of : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\ysb_regular[1].cab/ysbactivex.dll -> TrojanDownloader.IstBar : Ignored
C:\RECYCLER\S-1-5-21-2340129782-1656844410-259134454-1006\Dc11.txt -> Spyware.Cookie.Revenue : Ignored
C:\RECYCLER\S-1-5-21-2340129782-1656844410-259134454-1006\Dc14.txt -> Spyware.Cookie.Abetterinternet : Ignored
C:\RECYCLER\S-1-5-21-2340129782-1656844410-259134454-1006\Dc17.txt -> Spyware.Cookie.Adserver : Ignored
C:\thin-85-1-x-x.exe -> Adware.BetterInternet : Ignored
C:\Wildmedia324.exe -> TrojanDownloader.Agent.ac : Ignored
C:\WINDOWS\Coder\_386-a2p-0-0-.exe -> Heuristic.Win32.Dialer : Ignored
C:\WINDOWS\system32\scdata.dll -> Dialer.Generic : Ignored
C:\WINDOWS\system32\sxayerxp.dll -> Spyware.Look2Me : Ignored
C:\WINDOWS\system32\SysWebTelecom.dll -> Dialer.Generic : Ignored
C:\WINDOWS\system32\wpnsrv.dll -> Spyware.Look2Me : Ignored
C:\WINDOWS\thin-137-3-x-x.exe -> Adware.BetterInternet : Ignored
C:\WINDOWS\webview.dll -> Spyware.WebDirectory : Ignored
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~751492.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~7713.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~774740.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~775420.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~785097.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~789539.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~798876.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~809715.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~823459.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~8253.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~833040.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~835139.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~863973.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~880132.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~901283.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~902166.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~902749.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~933947.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~936412.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~938526.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~940081.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~941369.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~946393.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~956194.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~960300.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~961810.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~966080.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~966318.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~977569.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~978722.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~982616.tmp -> TrojanDownloader.WinTool : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temp\~986231.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\5FF7DH8E\PopularScreenSaversInitialSetup1.0.0.8[1].exe -> TrojanDropper.FunWeb.a : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\5ODQCD8O\0006_adult[1].cab/istactivex.dll -> TrojanDownloader.IstBar.gu : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\5ODQCD8O\latina-66[1].zip/latina-66/images/top_avi.exe -> Dialer.Generic : Error during cleaning
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\7N5F750W\mtrslib2[1].js -> TrojanDownloader.Small.ag : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\G1AV4TEJ\laura-angel[1].htm -> Not-A-Virus.Exploit.HTML.IframeBof : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\G1AV4TEJ\laura-angel[2].htm -> Not-A-Virus.Exploit.HTML.IframeBof : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\J6H0LJ7V\thnall1ac[3].htm -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\J6H0LJ7V\thnall1ac[4].htm -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\J6H0LJ7V\thnall1a[2].htm -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\MQ65KE11\HLInstaller3[1].exe -> Spyware.iSearch : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\867[1].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\867[2].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\867[3].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\hp2[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\instalador[1].cab/DownloadHtml.dll -> Spyware.Ruboskizo : Error during cleaning
C:\Documents and Settings\Jeison Rafe\Local Settings\Temporary Internet Files\Content.IE5\SDEBG56V\thnall1ac[3].htm -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6BC3SL2F\loadppc[1].exe -> TrojanDropper.Small.abx : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6RG5SR4P\load02[1].exe -> TrojanDropper.Small.aad : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\05KHQ3GX\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\09ENGDU7\consumerinfo2[1].htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0D8B8ROJ\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5C43P5KP\freetrial[1].exe -> TrojanDropper.Small.nm : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\69KFYHY5\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\69KFYHY5\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6HS72P25\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8LEN4HIN\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8VPRMQB1\exitpop[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8ZRJQC9L\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8ZRJQC9L\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9WA6SN7L\b_052000_com[1].htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9WA6SN7L\xload[1].exe -> TrojanDownloader.VB.kq : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9WA6SN7L\xload[2].exe -> TrojanDownloader.VB.kq : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9WA6SN7L\xload[3].exe -> TrojanDownloader.VB.kq : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9WA6SN7L\xload[4].exe -> TrojanDownloader.VB.kq : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\CRHV6YJL\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\CRHV6YJL\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GJ1VM2N1\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GTIVOHIN\sbar[1].exe -> TrojanDownloader.Tibser.c : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\H7NRLL0E\empty[2].html -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\IH4V25Y5\c_025000_com[2].html -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\O5GVWF4V\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\O9MBS9EF\Installer3[1].exe -> TrojanDropper.Delf.dj : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\S5IB4L2Z\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\S5IJODI7\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SNDNEQVX\hp2[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SNDNEQVX\hp2[2].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SXQVKHYN\hp2[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\U8MZEX3T\empty[2].html -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\V9OFDJ6C\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VFTNNPOW\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VFTNNPOW\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VFTNNPOW\exitpoplight1[3].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WXIBOXYV\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WXIBOXYV\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WXIBOXYV\win32[1].exe -> TrojanDownloader.Small.agq : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\YXJOH8Z6\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\YXJOH8Z6\exitpoplight1[2].htm -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Owner\My Documents\Jeison Documents\my software\od-stnd379.exe -> Dialer.Generic : Cleaned with backup
C:\hol5569203.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\install_george.exe -> Spyware.PurityScan : Cleaned with backup
C:\Program Files\Common Files\uwkw\uwkwl.exe -> TrojanDownloader.TSUpdate.j : Cleaned with backup
C:\Program Files\Common Files\uwkw\uwkwp.exe -> Spyware.Xupiter : Cleaned with backup
C:\Program Files\FileSubmit\Silvia Saint version 2\NNEZTA388.exe -> Spyware.NewDotNet : Cleaned with backup
C:\Program Files\FileSubmit\Silvia Saint version 2\TBEZA127Q.exe -> Spyware.Quick : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\01C28F79-6E55-4C75-8C81-21B403\8914A613-D0E7-417D-8BE8-4C3F93 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0BFCD7F1-C267-40ED-A6B3-56691C\8CB6A37E-8E97-4FF1-90A1-D7960D -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\2FE26069-488C-49D2-8FA1-D2867E\2FC6C3A2-4863-451B-8634-6650BD -> Spyware.NavExcel : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\91D0BD93-5C8A-407C-A9DD-CE48FD\9C69FDB4-1C62-4597-A024-6CE825 -> Trojan.Agent.fc : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\05AA7DBE-739E-4127-8A18-B765DA -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\14850C43-120E-4E39-81DD-49234F -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\1C49B400-DBA9-4F34-93C3-2C2F74 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\26651DD2-D473-49F7-A7F2-6D7408 -> TrojanDownloader.Qoologic.x : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\2AEBEDF0-42AC-4CA3-9F22-85FFC3 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\586632D7-4B49-4662-9329-B4E3D3 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\A0BD6B63-338E-4DD1-80C5-B29A11 -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\A291342B-F40C-4A9C-8F01-7C18EB -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\A942E97A-DA97-4880-8799-8C38FC -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\AC50DEA5-0856-43C5-880D-E1D4A6 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\C5663719-6169-485F-849E-8D1C51 -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B6D88575-D926-4A19-B251-08D3F7\DFA1A3DB-76BE-42AC-B3D9-B605AC -> TrojanDownloader.Qoologic.x : Cleaned with backup
C:\RECYCLER\S-1-5-21-2340129782-1656844410-259134454-1006\Dc1.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\WINDOWS\1jJO.exe -> Adware.MidADle : Cleaned with backup
C:\WINDOWS\69632 -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\assest.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\AktiveSekurity.ocx -> Not-A-Virus.VirTool.Collector : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\IberoDialerHTML.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\iNetPal\EZThemes_m3tsp8.exe -> TrojanDownloader.Agent.er : Cleaned with backup
C:\WINDOWS\jaaste.dll -> Trojan.Agent.fc : Cleaned with backup
C:\WINDOWS\LastGood\enhuninstall.exe -> Spyware.NoName : Cleaned with backup
C:\WINDOWS\rWeBd80u.exe -> Adware.MidADle : Cleaned with backup
C:\WINDOWS\sasetup.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\svchost.exe -> Backdoor.Rbot.azy : Cleaned with backup
C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ahifile.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\e4202efmgh2a2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\fp2s03f7e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\g4jole131h.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ir20l5fm1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\plflbmsg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\PreUninstall.exe -> Spyware.Suggestor : Cleaned with backup
C:\WINDOWS\system32\r4r6le9s1h.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wapitr.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\wlnipsec.dll -> Spyware.Look2Me : Cleaned with backup
::Report End
Edited by jeragu, 04 August 2005 - 03:06 PM.