ok, here is the HJT file and the ewido file
Logfile of HijackThis v1.99.1
Scan saved at 1:16:33 AM, on 8/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Windows\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\MI6841~1\80\Tools\binn\sqlservr.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\MSSearch\Bin\mssearch.exe
C:\Windows\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.educationamerica.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.37.0.13:8080
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://www.neededware.comO16 - DPF: Ali Baba Slots TM by pogo -
http://slots.pogo.co...a-ob-assets.cabO16 - DPF: Backgammon by pogo -
http://gammon.pogo.c...n-ob-assets.cabO16 - DPF: Canasta by pogo -
http://canasta.pogo....a-ob-assets.cabO16 - DPF: Checkers by pogo -
http://game3.pogo.co...s-ob-assets.cabO16 - DPF: Dominoes by pogo -
http://game5.pogo.co...o-ob-assets.cabO16 - DPF: Euchre by pogo -
http://euchre.pogo.c...e-ob-assets.cabO16 - DPF: Fortune Bingo by pogo -
http://superbingo.po...o-ob-assets.cabO16 - DPF: Hearts by pogo -
http://hearts.pogo.c...s-ob-assets.cabO16 - DPF: High Stakes Pool by pogo -
http://game4.pogo.co...l-ob-assets.cabO16 - DPF: Jigsaw Detective by pogo -
http://game1.pogo.co...w-ob-assets.cabO16 - DPF: Lottso by pogo -
http://game1.pogo.co...o-ob-assets.cabO16 - DPF: Mah Jong Garden by pogo -
http://game4.pogo.co...g-ob-assets.cabO16 - DPF: Microsoft WFC Forms Designer - file://E:\VJ98\wfcforms.cab
O16 - DPF: NDWCab -
http://www.neededware.com/ndw4.cabO16 - DPF: Pai Gow by pogo -
http://game3.pogo.co...w-ob-assets.cabO16 - DPF: Payday FreeCell by pogo -
http://game5.pogo.co...l-ob-assets.cabO16 - DPF: Perfect Pair Solitaire by pogo -
http://waterwheel.po...l-ob-assets.cabO16 - DPF: Phlinx by pogo -
http://game4.pogo.co...r-ob-assets.cabO16 - DPF: Pop Fu by pogo -
http://popfu.pogo.co...u-ob-assets.cabO16 - DPF: Poppit TM by pogo -
http://game5.pogo.co...t-ob-assets.cabO16 - DPF: Spider Solitaire by pogo -
http://game1.pogo.co...r-ob-assets.cabO16 - DPF: Sweet Tooth TM by pogo -
http://sweettooth.po...h-ob-assets.cabO16 - DPF: Tri-Peaks by pogo -
http://game4.pogo.co...s-ob-assets.cabO16 - DPF: Tumble Bees by pogo -
http://jumbee.pogo.c...e-ob-assets.cabO16 - DPF: Visual Studio 6 Extensibility Libraries - file://E:\VJ98\vstudio6.cab
O16 - DPF: Word Whomp Whackdown by pogo -
http://game1.pogo.co...n-ob-assets.cabO16 - DPF: WordJong by pogo -
http://game5.pogo.co...g-ob-assets.cabO16 - DPF: World Class Solitaire by pogo -
http://klondike.pogo...s-ob-assets.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/pote_x.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1118752516994O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = NOR.local
O17 - HKLM\Software\..\Telephony: DomainName = NOR.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = NOR.local
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: NavLogon - C:\Windows\System32\NavLogon.dll
O23 - Service: Compaq Remote Diagnostics Enabling Agent (CpqDfwWebAgent) - Compaq Computer Corporation - C:\Windows\Cpqdiag\Cpqdfwag.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:24:25 PM, 8/5/2005
+ Report-Checksum: B6EF691A
+ Scan result:
C:\Documents and Settings\77lyncht\Cookies\77lyncht@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4kidpelpamdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4snd5klqaidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlouodzkaoa6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\77lyncht@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyejcpoeoqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\77lyncht\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\77lyncht\Local Settings\Temp\nsh_103.exe -> Spyware.Downloadware : Cleaned with backup
C:\Documents and Settings\77lyncht\Local Settings\Temp\nsh_107.exe -> Spyware.Downloadware : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkyojdjwapw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmysidjefpq-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiond5cepawdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkismc5saogudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoqlc5mdpw6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4glcpeapaydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4skdjwkqamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4wnd5acoq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkocnczofqqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoemc5ahpwqdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkogicpmhoqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkowocpwepgsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyghczohpawdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkygldjkapwqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4snd5klqaidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliagazaboqwdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlouodzkaoa6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyqgcpmhpa6dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiondzigqqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiuldpwgqqwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiwlcpidpgqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyepc5wapg2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyghczelqasdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyolc5ihoawdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\7845971.dll -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\cln16.tmp -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\nsh_117.exe -> Spyware.Downloadware : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\uninstall.exe -> Spyware.EliteBar : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4AT3XAJV\170[1].bin -> TrojanDownloader.Small.aal : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4AT3XAJV\29[1].bin -> TrojanDropper.Delf.z : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4AT3XAJV\51[1].bin -> TrojanDownloader.Apropo.ab : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\4HS7KRKR\replaceSearch[1].dll -> Spyware.ReSearch : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8DYFCHI3\AuroraHandler[1].dll -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8DYFCHI3\aurora[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8TMJ8PMN\172[1].bin -> TrojanDropper.Agent.hl : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8TMJ8PMN\177[1].bin -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8TMJ8PMN\TBPS[1].cab/TBPS.exe -> Spyware.WebSearch : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\AVY3YLUZ\boo[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\155[1].bin -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\2.8.7.4[1].exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\abiuninst[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\banner[1].cab/banner.dll -> Spyware.Banex : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\joysaver[1].cab/m67m.ocx -> Spyware.MediaMotor : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BI4BZ5SX\Setup[1].exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYRK9Q3\ca2[2].dll -> Spyware.SearchIt : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CTYRK9Q3\nsh_117[1].exe -> Spyware.Downloadware : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GDYBG5QN\142[1].bin -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GDYBG5QN\tb3[1].cab/toolbar.dll -> Spyware.WebSearch : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I85XMWWH\175[1].bin -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I85XMWWH\tct101[1].dll -> TrojanDownloader.Dyfuca.eg : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IG8RXS5T\135[1].bin -> TrojanDownloader.VB.eu : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IG8RXS5T\AproposClientInstaller[1].exe -> Trojan.Pakes : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\O92ZOH6B\DrPMon[1].dll -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SL4D6VWP\newmajorse2[1].cab/newmajorse2.txt -> Spyware.WebSearch : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SL4D6VWP\sfita[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SL4D6VWP\thnall4c[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJQNQPAB\Nail[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJQNQPAB\Poller[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJQNQPAB\sfi2[1].dll -> Spyware.SearchIt : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ptnp.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Documents and Settings\eivory\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\eivory\Local Settings\Temp\tp7543.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Documents and Settings\eivory\Local Settings\Temporary Internet Files\Content.IE5\UXMJGTGP\2.8.7.4[1].exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\LastGood\buddy.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\LastGood\ceres.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\sfita.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\aojalo.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\bvpby.dat -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\ca2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\Cache\cxtpls_loader.exe -> TrojanDownloader.Apropo.ab : Cleaned with backup
C:\WINDOWS\system32\Cache\dist006.exe -> TrojanDownloader.VB.eu : Cleaned with backup
C:\WINDOWS\system32\Cache\HelperInstall.exe -> TrojanDropper.Delf.z : Cleaned with backup
C:\WINDOWS\system32\Cache\optimize4.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\WINDOWS\system32\Cache\optimize6.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\WINDOWS\system32\Cache\pi1_60.exe -> TrojanDownloader.Small.aal : Cleaned with backup
C:\WINDOWS\system32\Cache\smsca.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\Cache\ven_d1.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\system32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\datadx.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\gaatqxg.exe -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\system32\jldjwld.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\objok.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\robrqob.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\sfi2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\sgatne.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\sgatneaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\WinStat11.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\WinStat12.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\wzxitn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\tct101.dll -> TrojanDownloader.Dyfuca.eg : Cleaned with backup
C:\WINDOWS\zdqmcz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\aojalo.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\bvpby.dat -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\ca2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\Cache\cxtpls_loader.exe -> TrojanDownloader.Apropo.ab : Cleaned with backup
C:\WINDOWS\system32\Cache\dist006.exe -> TrojanDownloader.VB.eu : Cleaned with backup
C:\WINDOWS\system32\Cache\HelperInstall.exe -> TrojanDropper.Delf.z : Cleaned with backup
C:\WINDOWS\system32\Cache\optimize4.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\WINDOWS\system32\Cache\optimize6.exe -> TrojanDownloader.Dyfuca : Cleaned with backup
C:\WINDOWS\system32\Cache\pi1_60.exe -> TrojanDownloader.Small.aal : Cleaned with backup
C:\WINDOWS\system32\Cache\smsca.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\Cache\ven_d1.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\system32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\datadx.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\gaatqxg.exe -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\system32\jldjwld.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\objok.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\robrqob.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\sfi2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\sgatne.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\sgatneaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\WinStat11.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\WinStat12.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\wzxitn.exe -> Adware.BetterInternet : Cleaned with backup
::Report End