seems like trojan infection
fresh logs:
Logfile of HijackThis v1.99.1
Scan saved at 20:02:12, on 2005-08-17
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\STANLEY\Pulpit\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gazeta.pl/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [sysch.exe] C:\WINDOWS\sysch.exe
O4 - HKLM\..\Run: [sdkdg32.exe] C:\WINDOWS\sdkdg32.exe
O4 - HKLM\..\Run: [netsa32.exe] C:\WINDOWS\netsa32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1021.dll,InstantAccess
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) -
http://secure2.comne...iveSecurity.cabO16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
http://skaner.mks.co...kanerOnline.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{4C6F22AA-3F40-4CC2-8BC0-48CB8F5346A3}: NameServer = 192.168.0.249
O17 - HKLM\System\CS1\Services\Tcpip\..\{4C6F22AA-3F40-4CC2-8BC0-48CB8F5346A3}: NameServer = 192.168.0.249
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Network Security Service ( 11Fßä#·şÄÖ`I) - Unknown owner - C:\WINDOWS\system32\winpd32.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 19:55:47, 2005-08-17
+ Report-Checksum: B2261116
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{36846EB6-C1B1-A145-B3CE-F5740FA22FF8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{497AEAF3-0F8F-A4B6-48F2-A80144D90604} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{50AD557E-3426-41FD-AFDD-2AF39BB1C387} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{98832348-0E38-D102-51A5-517934760119} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A1BD0D9E-655B-CB60-6F75-1DFC720AEAB9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{ACB3E0B7-7D0C-40B7-99B3-3EEACDF86BFB} -> Spyware.Slagent : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D063E7A9-F6B2-80F8-44B2-F8210FDEDF67} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D25A4A72-58EB-1395-AF54-321D1954EE5B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EDE4719B-AC04-9EE1-7AEA-7712560B2832} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0594AF7E-573B-40DF-8165-E47AB2EAEFE8} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{469C7080-8EC8-43A6-AD97-45848113743C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{50AD557E-3426-41FD-AFDD-2AF39BB1C387} -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\ieki.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winpd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3jr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ipqu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\winck32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcxq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcel.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\syshl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysjp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cruq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netta.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addls.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netil.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atlya.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysyr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntfl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crri.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcgg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntvc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ievu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apiyy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcse32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javaki32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atlfx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ieen32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msip32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3cd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mssc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netiv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addrk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crst.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysai32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msui.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winig32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crvj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iedu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysgh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appob32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipzf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apitf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javamb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieou.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntku32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieri32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaib.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaid32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysiu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntlm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apilj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addvw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ay.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apild.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javabi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkfw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msvd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlzp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crwn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iphm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkle.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipbc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iebu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ue32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bmcqhs.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\full.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\WINDOWS\jnayml.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\etyeqa.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\njomrc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iewp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netgg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ncdarn.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fiyewg.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nxuxrx.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gymklh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yhxnhj.log -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bwnqaq.txt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mbkvwh.log -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cbrrdk.log -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bfsczc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javafv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\criq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\eoxtvc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wbtezw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zypccr.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcex.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qnifgf.txt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wvshis.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\rryvcd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crew32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javaru.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mgsyvf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ogoejd.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fzmhmy.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iobkii.log -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipgj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nxxxft.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\hftmip.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winhv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\delsmd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\olqisk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crgt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vtsrab.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieju32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\blffje.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\gtvdtd.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appew.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vikeob.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tltklm.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\muucfk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qwsvlq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apisx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aojkeq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\gvarol.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkil32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknnk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appim.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\okaafa.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winpz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\lkgtoh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crgo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\omciad.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bqwedv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkml.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\yayois.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zldqkv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcfi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\xfdanl.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\viyehv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appnd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apier.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\qfltdv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ryqvgz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javagl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\isyzzz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntjm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ihhdqt.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wybegl.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\jzmfsw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\drgfwx.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\xrhzqo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\dklzga.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysyi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\qnxwfh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rxlyhk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\xqbbsa.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\liksvo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdksy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcki.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tavrgf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntas32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ujfnvs.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vukpfw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ivihre.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\krzefw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkov.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hymlsa.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iemi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\jonbbh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atisfo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkpk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sirwwi.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlum32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\taeyyl.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkto32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ofekki.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\itnjvo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\pxrnvl.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkzl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dsxjxs.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ybgsgs.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\elcdzw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkyn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netdb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\qiwdjd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rscftg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mscr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\laoylp.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cdilvr.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\dwnnfu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\d3cl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nwmoiz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ytacuv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zlnwey.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crvt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\jlbnsc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\jdghvf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\lytaqz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fjzued.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\gbfwgg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfccs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iedj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\prpdql.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rzsvyq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\jvjdyb.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fnestv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\kijaaj.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ytfsod.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zmtuyg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yxjcuu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yiowex.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntyn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\rnbyep.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ituivf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\jtioxc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zmtbqm.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appfe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bfiwur.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iegs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dkwngc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\neter32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ysumib.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ylagkf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addvg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nffcnm.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\oytxpp.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieyc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\azwbqd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipmh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\pokxhz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atldk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gywsbq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\skrwcr.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vfuuup.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiug32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mnovcd.log -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\snajhi.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cncbiu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\thwpuc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bfmijq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\osxikh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\jirfvf.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlkg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gqgfxr.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\idyvlr.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ivvwji.dat -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipza32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\kpivnb.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netvb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018650.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018684.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018743.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018744.EXE -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018757.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018758.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018759.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018787.dll -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{D77E8417-A753-4865-9CC5-3C4F92987A09}\RP192\A0018788.exe -> Trojan.Small.ev : Cleaned with backup
::Report End