Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Invalid BackWeb Application ID 137903 [RESOLVED]


  • This topic is locked This topic is locked

#1
lyfelton

lyfelton

    Member

  • Member
  • PipPip
  • 50 posts
I have only posted to this log twice and each time I have had some excellent help. I am working on a friends computer and after finding alot of maleware her processor is still slow and I have a little trouble connecting to the internet sometimes. It is also vey slow and I think the Ewido scan is making the processer go up and down on the memory usage.

I followed all the instructions in the Click here section and it still appears to have a problem. Please help me figure this out. I have posted my hijack log and my scan log. Thank you so much in advance!!

Logfile of HijackThis v1.99.1
Scan saved at 9:09:33 PM, on 9/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLServiceHost.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wmkjnbdkg...pUJv7eY7Xo.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashTEnhancer Ext - {D7E588AB-A5D9-4422-B313-22A3470F9700} - c:\Program Files\Ftk\ftk.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123867074\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [vernn16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\vernn16.dll
O4 - HKCU\..\Run: [kvern16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\kvern16.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125026837703
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia...ll/pcs_0026.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:50:02 AM, 9/8/2005
+ Report-Checksum: F771FEF5

+ Scan result:

HKLM\SOFTWARE\BPT -> Spyware.BroadcastPC : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0007522A-2297-43C1-8EB1-C90B0FF20DA5} -> Spyware.ShopNav : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{421A63BA-4632-43E0-A942-3B4AB645BE51} -> Spyware.InternetWasher : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\unebmm350 -> Spyware.MoneyMaker : Cleaned with backup
HKLM\SOFTWARE\skin -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-2112709986-466280703-254042914-1003\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2112709986-466280703-254042914-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
C:\Program Files\Common Files\Java\bpcv2_inst.exe -> Spyware.Broadcap.d : Cleaned with backup
C:\Program Files\STC\msbb_install.exe -> Trojan.SecondThought.ab : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADBN3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADTMI1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIB9894.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIC29667.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASID12180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIE17070.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF29819.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF4502.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFA15376.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIG21943.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH21180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH7853.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASII21469.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIL18549.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASILS29399.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM4381.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM9740.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS24110.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS31590.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT17011.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT26116.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIW11211.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DENT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FMND1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEAL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEBE3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOGAR3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INSUR4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPR3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL6.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVEN1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\VENUE1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WOMEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WWW3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe -> Not-A-Virus.Downloader.Agent.c : Cleaned with backup
C:\WINDOWS\hihdwp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\exact.dll -> TrojanDownloader.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\midad.dll -> TrojanDownloader.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\midad0406.dll -> TrojanDownloader.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\scopenr.dll -> TrojanDownloader.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\ssk.dll -> TrojanDownloader.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\temp532.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\tv2.dll -> TrojanDropper.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\tv3.dll -> TrojanDropper.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\tvnew.dll -> TrojanDropper.Miewer.a : Cleaned with backup
C:\WINDOWS\system32\vern16.dll -> TrojanDropper.Miewer.d : Cleaned with backup


::Report End


Thanks so much
Lyfelton


09/16/2005

Since no one has replied to my log yet I will post an updated hijack log.
Logfile of HijackThis v1.99.1
Scan saved at 6:17:41 PM, on 9/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wmkjnbdkg...pUJv7eY7Xo.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashTEnhancer Ext - {D7E588AB-A5D9-4422-B313-22A3470F9700} - c:\Program Files\Ftk\ftk.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123867074\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [vernn16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\vernn16.dll
O4 - HKCU\..\Run: [kvern16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\kvern16.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125026837703
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia...ll/pcs_0026.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Hope you can help me get rid of this Invalid Backweb Application ID 137903 and help me speed up this PC.

Lyfelton again

Edited by lyfelton, 16 September 2005 - 04:27 PM.

  • 0

Advertisements


#2
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi There :)

let me have a look through your log and I will get the fix sorted out for you as soon as I can :tazz:

UKBiker
  • 0

#3
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Thanks so much. Hopefully you can help me. I appreciate it.

Lyfelton :) :tazz:
  • 0

#4
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi there :)

I am UKBiker and I will be helping you with this log.

Please print these instructions out as you will need to refer to them in safe mode later when access to the net is not available.

Step #1

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wmkjnbdkg...pUJv7eY7Xo.html
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: FlashTEnhancer Ext - {D7E588AB-A5D9-4422-B313-22A3470F9700} - c:\Program Files\Ftk\ftk.dll (file missing)
O4 - HKCU\..\Run: [kvern16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\kvern16.dll
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia...ll/pcs_0026.exe


[/b]Now close all windows other than HiJackThis, then click Fix Checked.

Step #2

Reboot into safe mode.(Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.)

Please delete these folders using Windows Explorer(if present):

c:\Program Files\Ftk

Please delete these files using Windows Explorer(if present):

C:\WINDOWS\System32\kvern16.dll
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

Step #3

After that, Reboot.

Step #4

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Step #5

Please reboot then rescan with HJT and post me a new logfile along with the results of the kaspersky scan.

Good Luck :tazz:

UKBiker
  • 0

#5
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Thanks so much UK Biker!!!

I followed your instructions and her are the new logs.

Logfile of HijackThis v1.99.1
Scan saved at 10:42:48 PM, on 9/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLServiceHost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123867074\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [vernn16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\vernn16.dll
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125026837703
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

And her is the Kasper scan log as well per your instructions.

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Saturday, September 17, 2005 22:18:57
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 17/09/2005
Kaspersky Anti-Virus database records: 149729
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 98777
Number of viruses found: 152
Number of infected objects: 995
Number of suspicious objects: 0
Duration of the scan process: 5016 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Alicia\Desktop\ss.exe Infected: not-a-virus:AdWare.AdURL.a
C:\Program Files\HP\Digital Imaging\bin\lopr.exe Infected: Trojan-Downloader.Win32.Swizzor.cg
C:\Program Files\Norton AntiVirus\Quarantine\2C250A37 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\473C02CB Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton AntiVirus\Quarantine\47402CC8 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\474356C4 Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474600C0 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\47492ABD Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474D54B9 Infected: not-a-virus:AdWare.VirtualBouncer.a
C:\Program Files\Norton AntiVirus\Quarantine\577344BD Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\5A71138E.exe Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\71ED6836 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\Norton AntiVirus\Quarantine\73CB5344 Infected: Trojan-Downloader.Win32.Agent.aa
C:\Program Files\Norton AntiVirus\Quarantine\73FC490E Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\745E34A2 Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\7D175BF7 Infected: Trojan.Win32.SecondThought.c
C:\Program Files\Norton AntiVirus\Quarantine\7D7D2435 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\7F5E2A48 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\007E51F3.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\009B71EF.exe Infected: Trojan-Downloader.Win32.Swizzor.bz
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09237244.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\094453BD.dll Infected: Trojan-Downloader.Win32.Miewer.e
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\094453BD.exe Infected: Trojan-Downloader.Win32.Swizzor.ca
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09AA49C4.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A103FCC.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A103FCC.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A7635D4.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A8D506A.exe Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0ADC2BDB.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0B4221E3.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0C0F0DF2.exe Infected: not-a-virus:AdWare.BetterInternet
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0C9223F6.exe/data0002 Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0C9223F6.exe Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0F7C098A.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\11AE2265.exe/data0004 Infected: not-a-virus:AdWare.Broadcap.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\11AE2265.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\14257EF6.dll Infected: not-a-virus:AdWare.Suggestor.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\153A05C3.exe Infected: not-a-virus:AdWare.BetterInternet
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\154C66D5.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\166D67DA.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\16D35DE1.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\179F49F0.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\18225FF4.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\18CE7461.dll Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1B09690D.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1B4550F1.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1CAB48A6.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E3A07AB.exe Infected: not-a-virus:AdWare.Lop.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1FEE465D.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20CB41C2.exe/data0004 Infected: not-a-virus:AdWare.Broadcap.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20CB41C2.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\213137C9.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21972DD1.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21FD23D8.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\226319E0.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23040DFC.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\232F05EF.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23B21BF3.exe Infected: Trojan-Downloader.Win32.Swizzor.cc
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\24DC7F7D.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\255A59A7.exe Infected: not-a-virus:AdWare.Lop.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\270F1859.exe Infected: not-a-virus:AdWare.Pacer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\27E04DBE.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\29A0583D.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2BB80DC5.dll Infected: Trojan-Downloader.Win32.Miewer.e
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2BFD5179.dll Infected: Trojan-Downloader.Win32.Qoologic.p
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2C5B7DC0.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2C7A2BA3.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D2769CF.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D8D5FD7.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D8D5FD7.exe Infected: not-a-virus:AdWare.WinFetcher.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2DF355DF.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2F2637F5.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2F4357F2.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\335A522E.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34B73270.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\354F3C50.exe Infected: not-a-virus:AdWare.Pacer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\37EB39BF.exe Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38512FC7.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38B725CE.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39175466.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\391E1BD6.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\391E1BD6.exe/data0002 Infected: Trojan.Win32.Starter.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\391E1BD6.exe Infected: Trojan.Win32.Starter.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\393A1085.dll Infected: Trojan-Dropper.Win32.Miewer.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\398411DD.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39952820.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39952820.exe Infected: Trojan-Downloader.Win32.Qoologic.n
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\399F2615.exe Infected: Trojan-Downloader.Win32.Apropo.ai
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39A35012.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39A35012.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39A67A0E.exe Infected: not-a-virus:AdWare.BetterInternet
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39A9240B.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39AC4E07.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39B07803.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39B32200.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39B64BFC.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39B975F9.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39BD1FF5.exe Infected: not-a-virus:AdWare.BetterInternet
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39C049F1.exe Infected: not-a-virus:AdWare.BetterInternet.i
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39C373EE.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39C61DEA.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39CA47E7.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39CD71E3.exe Infected: not-a-virus:AdWare.BetterInternet.l
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39EE15BF.exe/data0000.bin Infected: Trojan-Downloader.Win32.Apropo.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39EE15BF.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F13FBC.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F13FBC.exe Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F469B8.cfg Infected: not-a-virus:AdWare.Broadcap.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F713B4.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F713B4.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39F831BC.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39FB3DB1.cpl Infected: Trojan-Downloader.Win32.Qoologic.p
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39FB3DB1.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39FE67AD.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\39FE67AD.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0111AA.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0111AA.exe Infected: Trojan-Downloader.Win32.Intexp.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A053BA6.exe Infected: Trojan-Downloader.Win32.Intexp.e
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0865A2.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0865A2.exe Infected: Trojan-Downloader.Win32.Intexp.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0B0F9F.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0E399B.Dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A0E399B.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A126398.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A150D94.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A183790.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A1B618D.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A1F0B89.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A223586.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A255F82.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A28097E.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A2C337B.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A2F5D77.dll Infected: not-a-virus:AdWare.BHO.NoName.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A320774.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A320774.exe Infected: Trojan-Dropper.Win32.Agent.ij
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A363170.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A395B6C.cfg Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A395B6C.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A395B6C.exe Infected: Trojan.Win32.Starter.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A3C0569.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A3F2F65.exe Infected: Trojan.Win32.SecondThought.aa
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A435962.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A492D5A.cab/HyperLinker.exe Infected: not-a-virus:AdWare.MDH.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A492D5A.cab Infected: not-a-virus:AdWare.MDH.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A492D5A.exe Infected: not-a-virus:AdWare.MDH.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A4C5757.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A4C5757.exe Infected: Trojan-Downloader.Win32.Adload.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A500153.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A532B50.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A56554C.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A597F49.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A597F49.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A5D2945.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A605341.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A637D3E.exe Infected: not-a-virus:AdWare.BetterInternet.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A66273A.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A66273A.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A6A5137.exe Infected: not-a-virus:AdWare.Pacer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A6D7B33.exe Infected: not-a-virus:AdWare.Pacer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A70252F.exe Infected: not-a-virus:AdWare.Apropos.o
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A744F2C.dll Infected: Trojan-Dropper.Win32.Miewer.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A777928.dll Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A777928.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A7D4D21.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A7D4D21.exe Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A81771D.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A81771D.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A84211A.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A84211A.exe Infected: Trojan.Win32.Agent.az
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A874B16.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A874B16.exe Infected: Trojan-Spy.Win32.VB.eh
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8A7513.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8A7513.exe Infected: Trojan-Downloader.Win32.Small.qn
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8E1F0F.dll Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8E1F0F.exe Infected: Trojan-Downloader.Win32.Swizzor.di
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A91490B.exe Infected: not-a-virus:AdWare.BetterInternet
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A947308.exe Infected: Trojan-Downloader.Win32.Qoologic.n
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A9B4701.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A9E70FD.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA11AF9.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA11AF9.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA544F6.exe Infected: Trojan-Downloader.Win32.Agent.ed
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA86EF2.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA86EF2.exe/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AA86EF2.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AAB18EF.exe Infected: not-a-virus:AdWare.PurityScan.w
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AAE42EB.dll Infected: not-a-virus:AdWare.WhileSurf.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AAE42EB.exe Infected: not-a-virus:AdWare.WhileSurf.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3AD313F0.exe Infected: Trojan-Downloader.Win32.Swizzor.dh
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3C6F0E4C.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3F8246BF.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\437C75BE.exe Infected: Trojan-Downloader.Win32.Intexp.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\43906048.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\43E26BC5.exe Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\444861CD.exe Infected: not-a-virus:AdWare.WinFetcher.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45144DDC.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\457A43E3.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\46841702.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\46CA45F6.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D081B91.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D270ED4.dll Infected: Trojan-Downloader.Win32.Agent.jt
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4DA568FE.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4F7227C4.dll Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\50A409DA.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\510B7FE2.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\519564DA.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\544760D0.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\54C53AFA.exe Infected: Trojan-Downloader.Win32.Swizzor.co
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\567979AB.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\58822001.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\58F0563C.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\59301022.dll Infected: Trojan-Downloader.Win32.Agent.jt
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B0263C2.exe Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B236F17.exe Infected: Trojan-Downloader.Win32.Agent.ti
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6832CC.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6832CC.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5BCF4FD2.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5C3545D9.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DEA3DF4.exe Infected: Trojan-Downloader.Win32.Swizzor.dp
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62434113.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64BA1DA3.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66931FC1.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66F915C9.dll Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\675F0BD0.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\67C501D8.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68212049.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\682B77DF.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69217041.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\697B79F2.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6BDA6F9F.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E514C2F.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\70241902.exe Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7083650A.dll Infected: Trojan-Downloader.Win32.Qoologic.p
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\70D30922.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72235BC0.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72235BC0.exe Infected: not-a-virus:AdWare.DelphinMediaViewer.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72CE7306.exe Infected: Trojan-Downloader.Win32.Swizzor.bz
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72DB1AF8.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72DF44F4.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72E26EF1.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72E842EA.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72EC6CE6.exe Infected: Trojan.Win32.Krepper.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72EF16E2.exe Infected: Trojan-Downloader.Win32.Swizzor.df
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72EF47CF.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72F240DF.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72F56ADB.exe Infected: not-a-virus:AdWare.Lop.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72F914D8.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72FA419B.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72FC3ED4.exe Infected: not-a-virus:AdWare.Lop.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72FF68D0.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\73553DD6.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\73A969EF.exe Infected: Trojan-Dropper.Win32.Small.ue
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\73BC33DE.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\742229E5.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\74881FED.exe Infected: not-a-virus:AdWare.BetterInternet.m
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\750B35F1.exe Infected: Trojan-Downloader.Win32.Swizzor.dh
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\75EF7854.exe Infected: Trojan-Downloader.Win32.Swizzor.df
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\773E7B7B.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7A1B1396.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7CFB7DB3.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7D104A50.exe Infected: Trojan-Downloader.Win32.Swizzor.cc
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7DB317BE.exe/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7DB317BE.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E1A0DC6.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E1A0DC6.exe/data0002 Infected: Trojan.Win32.Septic.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E1A0DC6.exe Infected: Trojan.Win32.Septic.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E8003CD.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7E8B3049.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7EE679D5.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7F4C6FDD.exe Infected: Trojan.Win32.StartPage.nk
C:\Program Files\STC\mindset.exe.tcf Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\tvs\BPCv2.Plugins.dll Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041561.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041565.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041571.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041581.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041664.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041669.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041683.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041700.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041705.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041718.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041740.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041749.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041754.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041765.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041787.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041799.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041810.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041814.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041824.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041825.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041834.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041845.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042841.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043842.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044843.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044849.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044859.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044865.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044866.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044867.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044877.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044901.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045905.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045923.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045977.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045978.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045983.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045995.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe Infected: not-a-vir
  • 0

#6
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi there again

ok we are getting there :tazz:

please print these instructions out.

rescan with HJT and place checkmarks against the following items

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...lion&pf=desktop
O4 - HKCU\..\Run: [vernn16.dll] C:\WINDOWS\System32\regsvr32.exe /s C:\WINDOWS\System32\vernn16.dll


Close all windows and browsers other than HJT and click on "fix checked", the exit HJT.

Reboot into safe mode and delete the following file using windows explorer.

C:\WINDOWS\System32\vernn16.dll

Then reboot into normal mode.

Please rescan with HJT and post me the new log here.

Good Luck

UKBiker
  • 0

#7
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Hello UK Biker,

I followed the instructions. I couldn't find vernn16.dll in the system32 folder. I also did a serch and it didn't come up.

This is the new log

Logfile of HijackThis v1.99.1
Scan saved at 11:09:09 AM, on 9/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLServiceHost.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123867074\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125026837703
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Lyfelton :tazz:
  • 0

#8
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi there :)

Looking good :tazz:

Can you please now get rid finally of everything that is held in your Norton Quarantine and then run the Kav online scan again for me, have it fix whatever it can and then post its log here for me?

UKBiker
  • 0

#9
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Hello UK Biker

I ran the Kasper scan again and the online scan just told me that I had alot of infections. It didn't fix anything.

Here is the new scan.

Logfile of HijackThis v1.99.1
Scan saved at 10:14:34 PM, on 9/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\112386~1\EE\AOLServiceHost.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123867074\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125026837703
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Let me know what I should do.

Lyfelton :) :tazz:
  • 0

#10
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Oh sorry forgot the Kav scan log.

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, September 18, 2005 22:12:29
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 19/09/2005
Kaspersky Anti-Virus database records: 149937
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 98881
Number of viruses found: 152
Number of infected objects: 993
Number of suspicious objects: 0
Duration of the scan process: 5264 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Alicia\Desktop\ss.exe Infected: not-a-virus:AdWare.AdURL.a
C:\Program Files\HP\Digital Imaging\bin\lopr.exe Infected: Trojan-Downloader.Win32.Swizzor.cg
C:\Program Files\Norton AntiVirus\Quarantine\2C250A37 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\473C02CB Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton AntiVirus\Quarantine\47402CC8 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\474356C4 Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474600C0 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\47492ABD Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474D54B9 Infected: not-a-virus:AdWare.VirtualBouncer.a
C:\Program Files\Norton AntiVirus\Quarantine\577344BD Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\5A71138E.exe Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\71ED6836 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\Norton AntiVirus\Quarantine\73CB5344 Infected: Trojan-Downloader.Win32.Agent.aa
C:\Program Files\Norton AntiVirus\Quarantine\73FC490E Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\745E34A2 Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\7D175BF7 Infected: Trojan.Win32.SecondThought.c
C:\Program Files\Norton AntiVirus\Quarantine\7D7D2435 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\7F5E2A48 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\STC\mindset.exe.tcf Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\tvs\BPCv2.Plugins.dll Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041561.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041565.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041571.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041581.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041664.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041669.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041683.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041700.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041705.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041718.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041740.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041749.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041754.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041765.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041787.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041799.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041810.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041814.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041824.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041825.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041834.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041845.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042841.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043842.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044843.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044849.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044859.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044865.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044866.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044867.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044877.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044901.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045905.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045923.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045977.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045978.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045983.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045995.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046003.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046007.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046008.dll Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046010.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046943.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046944.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047942.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047946.exe Infected: not-a-virus:AdWare.BetterInternet.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047947.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047948.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047950.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047951.exe Infected: Trojan-Downloader.Win32.Delmed.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0006.BIN Infected: not-a-virus:AdWare.VirtualBouncer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0007.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047957.exe Infected: not-a-virus:AdWare.BetterInternet.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047958.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047968.exe Infected: not-a-virus:AdWare.TotalVelocity.aj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047969.dll Infected: not-a-virus:AdWare.TotalVelocity.v
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047970.dll Infected: not-a-virus:AdWare.TotalVelocity.aj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047971.exe Infected: not-a-virus:AdWare.SaveNow.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047972.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047973.exe Infected: not-a-virus:AdWare.MDH.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047976.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047976.EXE Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048005.dll Infected: Trojan-Downloader.Win32.Agent.cu
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/exdl.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/mqexdlm.srg Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/exul.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/javexulm.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe/stream/data0001 Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe/stream Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048016.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048018.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048019.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048020.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048022.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048026.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048031.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048033.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048034.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048035.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048039.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048041.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048044.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048045.exe Infected: not-a-virus:AdWare.BetterInternet.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048048.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048049.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048054.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048059.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048060.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048062.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048066.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048068.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048069.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048071.exe Infected: Trojan-Downloader.Win32.Swizzor.dp
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048072.exe Infected: Trojan-Downloader.Win32.Swizzor.bz
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048073.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048074.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048075.exe Infected: Trojan.Win32.Krepper.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048076.exe Infected: not-a-virus:AdWare.Lop.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048077.exe Infected: Trojan-Downloader.Win32.Swizzor.df
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048078.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048080.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048081.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048082.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049051.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049052.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049053.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049054.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049056.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049060.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049063.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049066.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049067.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049068.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049070.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049073.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049076.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049080.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050059.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050062.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050063.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050064.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050065.exe Infected: not-a-virus:AdWare.DelphinMediaViewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0006.BIN Infected: not-a-virus:AdWare.VirtualBouncer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0007.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050074.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050075.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050079.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050083.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050085.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050086.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050088.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050091.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050093.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050096.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051081.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051082.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051083.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051232.DLL Infected: not-a-virus:AdWare.ClearSearch.x
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051234.DLL Infected: not-a-virus:AdWare.ClearSearch.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051235.DLL Infected: not-a-virus:AdWare.ClearSearch.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051236.EXE Infected: not-a-virus:AdWare.ClearSearch.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051237.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051238.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd/C:/WINDOWS/System32/nvms.dll Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd/C:/Program Files/NaviSearch/bin/nls.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051249.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051250.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051251.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051253.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051256.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051257.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052250.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052251.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052253.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052254.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052260.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053247.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053255.exe Infected: Trojan-Downloader.Win32.Agent.tv
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053257.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053586.DLL Infected: not-a-virus:AdWare.ClearSearch.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053587.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053588.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053589.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053590.exe Infected: not-a-virus:AdWare.BiSpy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053591.exe Infected: Trojan-Downloader.Win32.OneClickNetSearch.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053592.dll Infected: not-a-virus:AdWare.BiSpy.s
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053593.exe Infected: Trojan-Downloader.Win32.Qoologic.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053594.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053595.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053596.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053597.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053598.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053599.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053600.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053601.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053602.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053603.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053604.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053605.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053606.dll Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053607.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053609.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053610.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0002 Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053612.dll Infected: not-a-virus:AdWare.F1Organizer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053613.exe Infected: Trojan-Downloader.Win32.Apropo.s
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053614.exe Infected: Trojan-Downloader.Win32.Apropo.u
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053615.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053616.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053617.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053618.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053619.dll Infected: Trojan-Downloader.Win32.Qoologic.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053620.exe Infected: Trojan.Win32.Small.an
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053622.exe Infected: not-a-virus:AdWare.BargainBuddy.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053623.dll Infected: Trojan-Downloader.Win32.Qoologic.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053624.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053625.dll Infected: Virus.Win32.Porad.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053626.exe Infected: not-a-virus:AdWare.WebRebates.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053627.exe/enhtb.dll Infected: not-a-virus:AdWare.BHO.NoName.m
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053627.exe Infected: not-a-virus:AdWare.BHO.NoName.m
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053628.dll Infected: Trojan-Downloader.Win32.Qoologic.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053629.exe Infected: Trojan-Downloader.Win32.Intexp.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053630.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053631.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053632.exe Infected: not-a-virus:AdWare.MDH.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053633.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053634.dll Infected: Trojan-Spy.Win32.Idly.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053635.exe Infected: Trojan-Dropper.Win32.Small.kz
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053636.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053637.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053638.ocx Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053639.dll Infected: not-a-virus:AdWare.BiSpy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053640.srg Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053641.dll Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053642.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053644.ocx Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053645.exe Infected: not-a-virus:AdWare.F1Organizer.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053646.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053647.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053648.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053649.dll Infected: not-a-virus:AdWare.BiSpy.t
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053650.exe Infected: not-a-virus:AdWare.BiSpy.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053651.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053652.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053653.exe Infected: Trojan-Downloader.Win32.Stubby.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053654.exe Infected: Trojan.Win32.SecondThought.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053655.dll Infected: not-a-virus:AdWare.ToolBar.ImiBar.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053656.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053657.dll Infected: Trojan-Downloader.Win32.Miewer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053658.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053659.exe Infected: Trojan-Downloader.Win32.Qoologic.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053660.exe/data0002 Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053660.exe Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053661.exe Infected: Trojan-Downloader.Win32.Agent.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053662.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053663.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053664.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053665.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053666.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053667.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053668.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053669.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053670.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053671.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053672.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053673.cfg Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053674.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053675.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053676.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053677.exe Infected: Trojan-Clicker.Win32.VB.ex
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053678.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053680.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053680.EXE Infected: not-a-virus:AdWare.VirtualBouncer
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053681.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053682.exe Infected: Trojan-Downloader.Win32.GoldenPalace
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053683.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053684.exe/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053684.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053685.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053686.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053687.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053687.EXE Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053688.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053689.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053690.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053691.dll Infected: not-a-virus:AdWare.BiSpy.t
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053692.exe Infected: not-a-virus:AdWare.BiSpy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053693.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053694.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053695.exe Infected: Trojan-Downloader.Win32.OneClickNetSearch.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053696.dll Infected: Trojan.Win32.SecondThought.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053697.dll Infected: Trojan.Win32.SecondThought.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053698.exe Infected: Backdoor.Win32.Agent.co
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053699.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053700.dll Infected: not-a-virus:AdWare.BookedSpace.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053701.exe Infected: Trojan.Win32.Small.an
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053702.DLL Infected: not-a-virus:AdWare.ClearSearch.l
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053703.exe Infected: Backdoor.Win32.Ruledor.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053704.exe Infected: not-a-virus:AdWare.SaveNow.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053705.cfg Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053706.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053707.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053708.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053709.exe Infected: not-a-virus:AdWare.BHO.NoName.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0002 Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053711.exe Infected: not-a-virus:AdWare.F1Organizer.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053712.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053713.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053714.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053715.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053716.dll Infected: not-a-virus:AdWare.BiSpy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053717.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053718.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053721.exe Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053722.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053723.exe/systb.dll Infected: not-a-virus:AdWare.ToolBar.ImiBar.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053723.exe Infected: not-a-virus:AdWare.ToolBar.ImiBar.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053724.exe Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053725.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053725.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053726.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053727.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053728.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053729.exe Infected: Trojan-Downloader.Win32.Stubby.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053730.dll Infected: Trojan-Dropper.Win32.Small.la
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053731.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053732.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053733.exe Infected: not-a-virus:AdWare.BiSpy.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053734.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053735.exe Infected: Trojan-Downloader.Win32.Intexp.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053736.exe Infected: Trojan-Downloader.Win32.Qoologic.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053737.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053738.ocx Infected: Trojan-Downloader.Win32.Small.fi
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054106.dll Infected: Trojan-Dropper.Win32.Miewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054107.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054108.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054109.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054110.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054111.exe Infected: Trojan.Win32.SecondThought.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054113.cfg Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054114.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054115.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054116.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054116.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054117.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054118.cpl Infected: Trojan-Downloader.Win32.Qoologic.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054119.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054120.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054121.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054122.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054123.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054124.dll Infected: Trojan-Downloader.Win32.Qoologic.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054125.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054126.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054127.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054128.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054129.exe Infected: Trojan-Downloader.Win32.Intexp.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054130.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054131.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054132.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054133.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054134.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054135.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054136.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054137.Dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054138.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054139.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054140.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054141.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054142.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054143.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A005
  • 0

Advertisements


#11
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
After looking at the Kav scan it said I still had things in Quarentine. I deleted everything in there and I don't understand why it says it is still there. I am going to reboot again and look at the quarentine. Then run the scan again and post the scan log.
  • 0

#12
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
After I rebooted This is the kav scan.
Noyhing was in my quarentine.

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, September 19, 2005 01:12:13
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 19/09/2005
Kaspersky Anti-Virus database records: 149958
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 98942
Number of viruses found: 152
Number of infected objects: 993
Number of suspicious objects: 0
Duration of the scan process: 5255 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Alicia\Desktop\ss.exe Infected: not-a-virus:AdWare.AdURL.a
C:\Program Files\HP\Digital Imaging\bin\lopr.exe Infected: Trojan-Downloader.Win32.Swizzor.cg
C:\Program Files\Norton AntiVirus\Quarantine\2C250A37 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\473C02CB Infected: not-a-virus:AdWare.VirtualBouncer.g
C:\Program Files\Norton AntiVirus\Quarantine\47402CC8 Infected: not-a-virus:AdWare.VirtualBouncer.d
C:\Program Files\Norton AntiVirus\Quarantine\474356C4 Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474600C0 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\47492ABD Infected: Trojan.Win32.SecondThought.ai
C:\Program Files\Norton AntiVirus\Quarantine\474D54B9 Infected: not-a-virus:AdWare.VirtualBouncer.a
C:\Program Files\Norton AntiVirus\Quarantine\577344BD Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\5A71138E.exe Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\71ED6836 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\Norton AntiVirus\Quarantine\73CB5344 Infected: Trojan-Downloader.Win32.Agent.aa
C:\Program Files\Norton AntiVirus\Quarantine\73FC490E Infected: Trojan-Downloader.Win32.Pluto
C:\Program Files\Norton AntiVirus\Quarantine\745E34A2 Infected: Trojan-Downloader.Win32.GoldenPalace
C:\Program Files\Norton AntiVirus\Quarantine\7D175BF7 Infected: Trojan.Win32.SecondThought.c
C:\Program Files\Norton AntiVirus\Quarantine\7D7D2435 Infected: Trojan.Win32.SecondThought.a
C:\Program Files\Norton AntiVirus\Quarantine\7F5E2A48 Infected: Backdoor.Win32.Ruledor.e
C:\Program Files\STC\mindset.exe.tcf Infected: Trojan.Win32.SecondThought.ab
C:\Program Files\tvs\BPCv2.Plugins.dll Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041561.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041565.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041571.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041581.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041664.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041669.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041683.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041700.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041705.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041718.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041740.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041749.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041754.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP158\A0041765.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041787.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP162\A0041799.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041810.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041814.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041824.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041825.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041834.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0041845.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0042841.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043831.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0043842.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044833.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044843.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044849.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044859.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044865.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044866.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044867.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP163\A0044877.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044901.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0044918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045905.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045906.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045918.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045923.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045977.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045978.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045983.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045995.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0045999.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046000.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046003.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046007.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046008.dll Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046010.exe Infected: not-a-virus:AdWare.Broadcap.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046943.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0046944.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047942.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047946.exe Infected: not-a-virus:AdWare.BetterInternet.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047947.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047948.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047950.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047951.exe Infected: Trojan-Downloader.Win32.Delmed.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0006.BIN Infected: not-a-virus:AdWare.VirtualBouncer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe/WISE0007.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047954.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047957.exe Infected: not-a-virus:AdWare.BetterInternet.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047958.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047968.exe Infected: not-a-virus:AdWare.TotalVelocity.aj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047969.dll Infected: not-a-virus:AdWare.TotalVelocity.v
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047970.dll Infected: not-a-virus:AdWare.TotalVelocity.aj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047971.exe Infected: not-a-virus:AdWare.SaveNow.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047972.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047973.exe Infected: not-a-virus:AdWare.MDH.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047976.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0047976.EXE Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048005.dll Infected: Trojan-Downloader.Win32.Agent.cu
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/exdl.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/mqexdlm.srg Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/exul.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd/C:/WINDOWS/System32/javexulm.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048009.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe/stream/data0001 Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe/stream Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048010.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048016.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048018.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048019.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048020.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048022.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048026.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048031.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048033.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048034.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048035.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048039.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048041.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048044.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048045.exe Infected: not-a-virus:AdWare.BetterInternet.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048048.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048049.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048054.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048059.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048060.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048062.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048066.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048068.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048069.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048071.exe Infected: Trojan-Downloader.Win32.Swizzor.dp
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048072.exe Infected: Trojan-Downloader.Win32.Swizzor.bz
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048073.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048074.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048075.exe Infected: Trojan.Win32.Krepper.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048076.exe Infected: not-a-virus:AdWare.Lop.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048077.exe Infected: Trojan-Downloader.Win32.Swizzor.df
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048078.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048080.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048081.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0048082.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049051.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049052.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049053.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049054.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049056.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049060.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049063.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049066.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049067.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049068.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049070.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049073.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049076.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0049080.exe Infected: not-a-virus:AdWare.AdURL.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050059.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050062.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050063.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050064.exe Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050065.exe Infected: not-a-virus:AdWare.DelphinMediaViewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0006.BIN Infected: not-a-virus:AdWare.VirtualBouncer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe/WISE0007.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050073.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050074.exe Infected: Trojan-Downloader.Win32.Delmed.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050075.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050079.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050083.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050085.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050086.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050088.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050091.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050093.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0050096.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051081.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051082.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051083.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051232.DLL Infected: not-a-virus:AdWare.ClearSearch.x
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051234.DLL Infected: not-a-virus:AdWare.ClearSearch.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051235.DLL Infected: not-a-virus:AdWare.ClearSearch.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051236.EXE Infected: not-a-virus:AdWare.ClearSearch.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051237.ocx Infected: not-a-virus:AdWare.DelphinMediaViewer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051238.dll Infected: not-a-virus:AdWare.DelphinMedia.Viewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd/C:/WINDOWS/System32/nvms.dll Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd/C:/Program Files/NaviSearch/bin/nls.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051240.vxd Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051249.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051250.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051251.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051253.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051256.dll Infected: not-a-virus:AdWare.FlashEnhancer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0051257.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052250.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052251.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052253.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052254.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0052260.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053247.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053255.exe Infected: Trojan-Downloader.Win32.Agent.tv
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP164\A0053257.dll Infected: Trojan.Win32.EliteBar.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053586.DLL Infected: not-a-virus:AdWare.ClearSearch.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053587.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053588.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053589.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053590.exe Infected: not-a-virus:AdWare.BiSpy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053591.exe Infected: Trojan-Downloader.Win32.OneClickNetSearch.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053592.dll Infected: not-a-virus:AdWare.BiSpy.s
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053593.exe Infected: Trojan-Downloader.Win32.Qoologic.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053594.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053595.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053596.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053597.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053598.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053599.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053600.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053601.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053602.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053603.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053604.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053605.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053606.dll Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053607.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053609.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053610.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0002 Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053611.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053612.dll Infected: not-a-virus:AdWare.F1Organizer.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053613.exe Infected: Trojan-Downloader.Win32.Apropo.s
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053614.exe Infected: Trojan-Downloader.Win32.Apropo.u
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053615.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053616.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053617.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053618.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053619.dll Infected: Trojan-Downloader.Win32.Qoologic.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053620.exe Infected: Trojan.Win32.Small.an
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053622.exe Infected: not-a-virus:AdWare.BargainBuddy.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053623.dll Infected: Trojan-Downloader.Win32.Qoologic.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053624.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053625.dll Infected: Virus.Win32.Porad.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053626.exe Infected: not-a-virus:AdWare.WebRebates.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053627.exe/enhtb.dll Infected: not-a-virus:AdWare.BHO.NoName.m
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053627.exe Infected: not-a-virus:AdWare.BHO.NoName.m
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053628.dll Infected: Trojan-Downloader.Win32.Qoologic.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053629.exe Infected: Trojan-Downloader.Win32.Intexp.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053630.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053631.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053632.exe Infected: not-a-virus:AdWare.MDH.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053633.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053634.dll Infected: Trojan-Spy.Win32.Idly.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053635.exe Infected: Trojan-Dropper.Win32.Small.kz
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053636.vxd Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053637.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053638.ocx Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053639.dll Infected: not-a-virus:AdWare.BiSpy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053640.srg Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053641.dll Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053642.exe Infected: not-a-virus:AdWare.180Solutions
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053644.ocx Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053645.exe Infected: not-a-virus:AdWare.F1Organizer.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053646.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053647.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053648.exe Infected: Trojan.Win32.Agent.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053649.dll Infected: not-a-virus:AdWare.BiSpy.t
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053650.exe Infected: not-a-virus:AdWare.BiSpy.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053651.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053652.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053653.exe Infected: Trojan-Downloader.Win32.Stubby.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053654.exe Infected: Trojan.Win32.SecondThought.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053655.dll Infected: not-a-virus:AdWare.ToolBar.ImiBar.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053656.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053657.dll Infected: Trojan-Downloader.Win32.Miewer.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053658.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053659.exe Infected: Trojan-Downloader.Win32.Qoologic.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053660.exe/data0002 Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053660.exe Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053661.exe Infected: Trojan-Downloader.Win32.Agent.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053662.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053663.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053664.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053665.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053666.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053667.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053668.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053669.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053670.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053671.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053672.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053673.cfg Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053674.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053675.exe Infected: not-a-virus:AdWare.BargainBuddy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053676.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053677.exe Infected: Trojan-Clicker.Win32.VB.ex
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053678.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053680.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053680.EXE Infected: not-a-virus:AdWare.VirtualBouncer
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053681.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053682.exe Infected: Trojan-Downloader.Win32.GoldenPalace
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053683.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053684.exe/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053684.exe Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053685.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053686.dll Infected: Trojan.Win32.StartPage.io
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053687.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053687.EXE Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053688.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053689.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053690.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053691.dll Infected: not-a-virus:AdWare.BiSpy.t
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053692.exe Infected: not-a-virus:AdWare.BiSpy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053693.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053694.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053695.exe Infected: Trojan-Downloader.Win32.OneClickNetSearch.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053696.dll Infected: Trojan.Win32.SecondThought.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053697.dll Infected: Trojan.Win32.SecondThought.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053698.exe Infected: Backdoor.Win32.Agent.co
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053699.cfg Infected: Trojan-Downloader.Win32.RVP.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053700.dll Infected: not-a-virus:AdWare.BookedSpace.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053701.exe Infected: Trojan.Win32.Small.an
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053702.DLL Infected: not-a-virus:AdWare.ClearSearch.l
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053703.exe Infected: Backdoor.Win32.Ruledor.e
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053704.exe Infected: not-a-virus:AdWare.SaveNow.ay
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053705.cfg Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053706.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053707.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053708.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053709.exe Infected: not-a-virus:AdWare.BHO.NoName.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0002 Infected: not-a-virus:AdWare.FlashTrack.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0003/data0001 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe/data0003 Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053710.exe Infected: not-a-virus:AdWare.Broadcap.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053711.exe Infected: not-a-virus:AdWare.F1Organizer.h
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053712.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053713.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053714.exe Infected: Trojan-Downloader.Win32.Agent.ae
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053715.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053716.dll Infected: not-a-virus:AdWare.BiSpy.n
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053717.exe Infected: not-a-virus:AdWare.BargainBuddy.q
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053718.exe Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe/data0001.cab Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053720.exe Infected: not-a-virus:AdWare.SaveNow.z
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053721.exe Infected: Trojan.Win32.Agent.az
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053722.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053723.exe/systb.dll Infected: not-a-virus:AdWare.ToolBar.ImiBar.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053723.exe Infected: not-a-virus:AdWare.ToolBar.ImiBar.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053724.exe Infected: not-a-virus:AdWare.Suggestor.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053725.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053725.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053726.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053727.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053728.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053729.exe Infected: Trojan-Downloader.Win32.Stubby.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053730.dll Infected: Trojan-Dropper.Win32.Small.la
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053731.exe Infected: Trojan-Downloader.Win32.Intexp.b
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053732.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053733.exe Infected: not-a-virus:AdWare.BiSpy.o
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053734.exe Infected: Trojan-Downloader.Win32.Stubby.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053735.exe Infected: Trojan-Downloader.Win32.Intexp.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053736.exe Infected: Trojan-Downloader.Win32.Qoologic.c
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053737.exe Infected: Trojan-Downloader.Win32.Intexp.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0053738.ocx Infected: Trojan-Downloader.Win32.Small.fi
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054106.dll Infected: Trojan-Dropper.Win32.Miewer.f
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054107.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054108.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054109.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054110.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054111.exe Infected: Trojan.Win32.SecondThought.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054113.cfg Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054114.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054115.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054116.exe/data0002 Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054116.exe Infected: not-a-virus:AdWare.Broadcap.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054117.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054118.cpl Infected: Trojan-Downloader.Win32.Qoologic.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054119.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054120.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054121.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054122.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054123.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054124.dll Infected: Trojan-Downloader.Win32.Qoologic.p
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054125.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054126.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054127.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054128.dll Infected: Trojan-Downloader.Win32.Miewer.a
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054129.exe Infected: Trojan-Downloader.Win32.Intexp.d
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054130.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054131.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054132.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054133.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054134.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054135.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054136.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054137.Dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054138.dll Infected: not-a-virus:AdWare.Look2Me.ab
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054139.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054140.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054141.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054142.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072-AA96-4495C42D15E3}\RP165\A0054143.exe Infected: Trojan.Win32.StartPage.nk
C:\System Volume Information\_restore{70304573-AB33-4072
  • 0

#13
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi there

almost done now, we just have a few files identified by the online scan to deal with.

I need some more info on these files in particular

Jotti File Submission:
  • Please go to Jotti's malware scan
  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page:
    • C:\Program Files\HP\Digital Imaging\bin\lopr.exe
  • Click on the submit button
  • Please post the results in your next reply.

Could you then repeat that process for this file path

C:\Documents and Settings\Alicia\Desktop\ss.exe



Also, can you tell me if you have an application called "Smooth Surfer" or similar installed, it is a pop up blocker I think.


UKBiker
  • 0

#14
lyfelton

lyfelton

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
I completed your instructions UK Biker

Here are the results

Service load: 0% 100%

File: lopr.exe
Status: INFECTED/MALWARE
MD5 71701df9d3518f8b09ac4f0cbfe99322
Packers detected: PE_PATCH.UPC, UPC
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Swizzor.cg
NOD32 Found probably a variant of Win32/TrojanDownloader.Swizzor (probable variant)
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing


This is Ss.exe

load: 0% 100%

File: ss.exe
Status: INFECTED/MALWARE
MD5 5375d517b79eb873ce2e3ed379614821
Packers detected: -
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.AdURL.a
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing


Also Smooth Surfer is not installed.

Lyfelton :tazz:
  • 0

#15
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi there :tazz:

Thanks for running those analysis for me.

Please boot into safe mode, then using windows explorer, delete the following files -


C:\Program Files\HP\Digital Imaging\bin\lopr.exe
C:\Documents and Settings\Alicia\Desktop\ss.exe

When you have done that, reboot into normal mode and re run the kaspersky scan for me again, posting the log as before.

Thanks

UKBiker
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP