Phil,
As requested. I did not find a number of the items to fix with HIJACKTHIS as you prescribed. Ewido found a bunch. I ddin't mention before, but explorer starts at boot time - still does. May new HIJACH log follows, follwed by the ewido log.
BTW - I appreciate your help!
Logfile of HijackThis v1.99.1
Scan saved at 9:40:24 PM, on 8/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Symantec\Ghost\ngctw32.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\TEMP\JE54C0.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\system32\pctspk.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\Program Files\Infotriever\Agent\infoclient.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://start.earthlink.netR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.earthlink...ton/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.excite.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\winnt\googletoolbar3.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\winnt\googletoolbar3.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe
/logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [CPortPatch] C:\WINNT\DockQuickInstall\cppch.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend
Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet
Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google
Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe
/c
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe
-quiet
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink
TotalAccess\TaskPanl.exe" -noauth
O4 - Startup: Infotriever.lnk = C:\Program
Files\Infotriever\Agent\infoclient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program
Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search -
res://c:\winnt\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program
Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links -
res://c:\winnt\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:\winnt\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://c:\winnt\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:\winnt\GoogleToolbar3.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program
Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite -
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft
ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft
ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -
C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
{4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program
Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) -
https://intecatl-tm1...ll/WinNTChk.cabO16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition
Web-Deployment SetupIniCtrl Class) -
https://intecatl-tm1...ll/setupini.cabO16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition
Web-Deployment SetupCtrl Class) -
https://intecatl-tm1...stall/setup.cabO16 - DPF: {2F824F9A-F14B-4847-83DE-616D7B589CD0} (Viair Address Book
Importer) -
https://nextel.wirel...s/addrbook2.cabO16 - DPF: {36E4E9BC-4D0C-41B4-90C9-37AFDBFAAD3C} (InforbitHelper Class) -
http://download.info...in/ifhelper.cabO16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) -
https://lnmail4.disc...com/iNotes6.cabO16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition
Web-Deployment ObjRemoveCtrl Class) -
https://intecatl-tm1.../RemoveCtrl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros.../client/wuweb_site.cab?1119099520849
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://beta.update.m.../x86/client/muweb_site.cab?1105900262919
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) -
http://download.zone...ctor/WebSWK.cabO16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) -
http://h30155.www3.h...edsolutions.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://intec-teleco...bex/ieatgpc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = git.compgen.com
O17 - HKLM\Software\..\Telephony: DomainName = git.compgen.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = git.compgen.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = git.compgen.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = git.compgen.com
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner -
C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc.
- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program
Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program
Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Symantec Ghost Client Agent (NGClient) - Symantec Corporation
- C:\Program Files\Symantec\Ghost\ngctw32.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. -
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc.
- C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. -
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
EWIDO LOG
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:16:22 PM, 8/22/2005
+ Report-Checksum: B778C01
+ Scan result:
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Ignored
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@serving-sys[4].txt -> Spyware.Cookie.Serving-sys : Ignored
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Ignored
:mozilla.10:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.11:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.12:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.13:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.16:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.17:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.18:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.19:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.20:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
:mozilla.21:C:\Documents and Settings\scott frey\Application Data\Mozilla\Firefox\Profiles\csbeln4s.default\cookies.txt -> Spyware.Cookie.Excite : Ignored
C:\Program Files\TightVNC\WinVNC.exe -> Backdoor.Vnc : Ignored
C:\Program Files\Nextel\Nextel Online Dialer\nol_svc2K.exe -> Heuristic.Win32.Dialer : Ignored
C:\Program Files\iPass\iPassConnect\idialer.exe -> Heuristic.Win32.Dialer : Ignored
HKLM\SOFTWARE\Classes\CLSID\{0AC06EDE-DB03-5DF7-8CBC-35C203487A0E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{10FE872A-F27F-5119-80CC-7906F4513EE9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{53B9EE38-47AC-238E-78A2-7AC3BDB37714} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8176A735-69C2-E35F-F5CE-1175658F52F7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E680E41-ECFF-E677-B3C2-F038A1610215} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DEFEF05D-61BA-2BFB-DB34-AB118C6A8498} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA171238-F541-7E67-9E3C-CDCC41E85D98} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FA171238-F541-7E67-9E3C-CDCC41E85D98} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-5914094-1725325479-1851928258-2331\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87067F04-DE4C-4688-BC3C-4FCF39D609E7} -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-5914094-1725325479-1851928258-2331\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-5914094-1725325479-1851928258-2331\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-5914094-1725325479-1851928258-2331\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FA171238-F541-7E67-9E3C-CDCC41E85D98} -> Spyware.CoolWebSearch : Cleaned with backup
C:\WINNT\SYSTEM32\netsw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\nethr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ntcm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\addjx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\addpv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appdg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\apift32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkeg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appsi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\apiun32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkta.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winid32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysyy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\syssy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcnc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ienp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ntpe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkyq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winff.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\addhw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netrv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcpq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ipvq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mstn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\apprr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkkl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netcj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\apiac32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkyy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\crng.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winao.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\d3ne32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcle32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appvl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ipcw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ipuu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\apims.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysgr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysgr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\ipvs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netem32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sdkuu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\crxp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\d3pj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcyv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysow.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\crzn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javaxw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysjg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\atlcf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netnd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcdt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appao32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\netzb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ipzr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\d3lb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javabq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\d3oa.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\ipud32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\d3vv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\iepg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winmk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winhc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\atlfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysnd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\appkr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javaxb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\mfcdd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\mfcdd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcoj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\iecd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\atlky32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\msoj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\appwe.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\d3zw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\ipnq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\addqj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\d3vd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\netbf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\addey32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\crjs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\iewu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winkx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\ntru.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\ntiq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javarm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\SYSTEM32\apiwg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javajw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\javawa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\msvy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mszs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\winzw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\mfcdy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\crtl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\addhe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\msaj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\SYSTEM32\sysxp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\Downloaded Program Files\ieatgpc.dll -> Spyware.WebEx : Cleaned with backup
C:\WINNT\igiqyk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\gdqtld.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\cwunf.dll -> Spyware.OneMoreSearch : Cleaned with backup
C:\WINNT\zlximb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nlcmfn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hnrled.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\euluph.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sujxnv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\gntnum.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ydebao.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ltveuz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\curqvi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\syskh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\sajauw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vsrqfy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fnigmh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oetccy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntzk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\yzxxgo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\javaqx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\iuonfx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\irzlne.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tcyzop.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\craw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\fiutwb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\qvdnhz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfcsw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\fnhdkz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ukxcai.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfcer32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\jzeraj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mriddv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\arnahj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appcc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\upccid.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zbfgif.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntuj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\thujiz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vidbjb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkcp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\rycpqt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\cnninh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfcbc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ephalw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\eolcxg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\chwprq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ifgnso.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\leoake.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xtqeib.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ipwy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\javazl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bmumrw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xlqbmq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\geyyng.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\javayl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\bszonj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tzweeu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\cgeqtk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\apijm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\qgjmqy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nsrdjs.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\busybw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kgrrtt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfgidx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nylcna.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\byqzjo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\lttqsj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tnnprc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wfhbuk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wzpefl.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\apiuo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\hvzirn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vpfftu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nwnqjk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bxrvfy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tpxpqb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\paamys.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appug32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\lruguf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mjhaxi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\swmeyl.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\apipw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\addvy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\vovygy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hgrjda.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sfrrxe.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\syswa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\kqwagd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\javajl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\chdiai.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vzjlkl.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wgklft.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ipwb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\xkvgml.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\grqxeb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hyyyzk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hjeajn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\msey32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\wjjacv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\d3sr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\uakndw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\winlo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\crik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\isgrhr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\crxf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\maxfoj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\qivsvb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\atlux32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\tquxct.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ipyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\zpdekr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appdm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\sndmev.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\idbbxy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkhv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\taglem.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zitpdi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mbxkdj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bjdiwk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vmobuf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ybzuru.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\lhdyxp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fvmzng.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\upsvpn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bzhkmd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\pzlojr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\uiuurk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\avzzkn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tczzfw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\yudlag.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oytadp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fkrhzc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\apiff.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\iseaxo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wvxbrf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkhf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vmcgoc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wfhizg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\iezt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\hyxspe.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\dxffzu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vmojqo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ximzny.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfczo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\uxmqub.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ofxrql.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3wr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\javaxp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\appur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ntkm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ntbt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\apilz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\oylzir.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fhpjlx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\addtt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ibyvrw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\javabp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ocmdjt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\auznfa.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\atlzv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\addxq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ngxqid.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\adxwti.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kajgrw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mfcoy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\vpoyyk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\atlmz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\iesc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntvu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appyf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mslh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\yhijss.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntrb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ippa32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appuu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3xn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ipdh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\addga.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3tc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\lcjstj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\apidm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rcigjk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\apiyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\hyyvet.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\renlal.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vrqtlk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\swagko.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oestkb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\syrooi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\keioqo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kjaohd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rqbvwd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sjgpzg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wnjazi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ilxlyq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xjhyuh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bxxlvf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rlscbr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\wqaimw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\winpx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\mfpxex.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\qsyzxc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zczrfp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sodxxy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3ic32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\wsyrpv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xldlzy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3dt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\pxdtwn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\lsbgau.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hjggsd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdjjxq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vrjwuz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ycyrfe.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ogogan.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\uzyfhe.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\jrlbdd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hdhsco.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\addvg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ntzc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ltpebm.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\dorhxo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zjbqjx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rowltc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\momgzp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\msgs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ajadux.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\dznzou.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zulmsb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sogsip.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oxrjmi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\iizcdc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkfl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\mfcpy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\otxjva.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\folafv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rgglzd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xzqcgu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sysyq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\winms32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\bqvytt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\tspenf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xagrvx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\yqfipr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\eeudhf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ttrfny.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\netxu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\krzhjj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\crht.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\cshtws.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ieam.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ykkifi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rtpgvh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3ym32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\onhcdo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sdkvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\imvwia.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bcoaaw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\appsn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\sqnlyx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\absnqo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\d3lg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\vllgks.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\winqi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\vbqiwc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\addyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\tdeqgz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\pnekyd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\llzwwt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ryeapw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sfnbkf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zgbxhv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nhgulj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kygilc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\qktmmg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\rrumho.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ztijee.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ntnfbs.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hbxgwc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ggxgyj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vdldzj.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oqldvz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sggptp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\zmyvxv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sszvre.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hcnspu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wwthrb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\cehlix.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\eeqejz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wrqmgp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bplydf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hcqcwi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ajzczr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hknzwg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vntwro.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kuzsqk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oetels.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\evitrm.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fuwnwq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kgrzor.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ikqgte.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nqmkrz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hdvlpq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wroctb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bpjnrr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hcosku.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\bbcupg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\icrrmw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\uulcpe.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\jdakny.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mhldmt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ppjqll.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vpoupz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\anjgnp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\wavvtz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\pzvdne.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\iuzkar.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\fndoeb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vislzk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\uujsvy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oxtltt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\sfszal.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\gfxvxz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\keahup.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\pwwtqz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\vjaxrc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oqjxmk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\emzmhu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\dzobxq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xyyuej.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\awsfix.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\nwxcfl.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\kmsvcc.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\qybcip.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hvzjbr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\xhedwz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\axxotn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\oxclpb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\svxwms.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\yobiib.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hxeslh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\hbacsy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\ldlzmi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\mhegqs.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\scott frey\Cookies\scott frey@excite[1].txt -> Spyware.Cookie.Excite : Cleaned with backup
C:\Documents and Settings\scott frey\Cookies\scott
[email protected][3].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\scott frey\Cookies\scott frey@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\scott frey\Cookies\scott
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\scott frey\Cookies\scott
[email protected][1].txt -> Spyware.Cookie.Excite : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@track-star[1].txt -> Spyware.Cookie.Track-star : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][1].txt -> Spyware.Cookie.Excite : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@specificpop[4].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott frey@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\scott frey\Application Data\Earthlink\6.0\
[email protected]\Cookies\scott
[email protected][3].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\Documents and Settings\scott frey\Appl