new hjt log:
Logfile of HijackThis v1.99.1
Scan saved at 22:14:44, on 14/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Jakes\Desktop\security suite\ewidoctrl.exe
C:\Documents and Settings\Jakes\Desktop\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Jakes\My Documents\All Mine\aim.exe
C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Jakes\Desktop\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {16875E09-927B-4494-82BD-158A1CD46BA0} - C:\WINDOWS\system32\prflbmsgp32.dll
O2 - BHO: C:\WINDOWS\q660062.dll - {7A7E6D97-B492-4884-9ABB-C31281DCC4F2} - C:\WINDOWS\q660062.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SupaDial] C:\Program Files\SupaDial\SupaDial.exe /A
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunServices: [Distributed Link Transfer Server] nega.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Documents and Settings\Jakes\My Documents\All Mine\aim.exe -cnetwait.odl
O4 - Global Startup: AudioDeck.lnk = C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Jakes\My Documents\All Mine\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.tiny.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO20 - Winlogon Notify: style32 - C:\WINDOWS\q660062.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\Jakes\Desktop\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Documents and Settings\Jakes\Desktop\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
ewido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 18:34:37, 14/10/2005
+ Report-Checksum: 4C220F7F
+ Scan result:
HKLM\SOFTWARE\Classes\AdmilliServX.Installer\CLSID\\ -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/AdmilliServX.dll\\.Owner -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/AdmilliServX.dll\\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy : Cleaned with backup
HKU\S-1-5-21-3984262255-3962308533-486386096-1007\Software\salm -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\system32\drivers\etc\hosts -> Trojan.Qhost : Cleaned with backup
C:\WINDOWS\system32\logon.exe -> Backdoor.Zins : Cleaned with backup
C:\WINDOWS\system32\bsc32.exe -> TrojanProxy.Agent.co : Cleaned with backup
C:\WINDOWS\system32\spoolsc -> Backdoor.Wootbot : Cleaned with backup
C:\WINDOWS\system32\exul1.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\adlinstallwin32.exe -> TrojanDownloader.Agent.jq : Cleaned with backup
C:\WINDOWS\system32\tcpG4T.dll -> TrojanSpy.Goldun.bp : Cleaned with backup
C:\WINDOWS\system32\msudp4.sys -> TrojanSpy.Goldun.bf : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\Iesearch.exe -> Backdoor.Zins : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\Iesearch.exe -> Backdoor.Zins : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\Iesearch.exe -> Backdoor.Zins : Cleaned with backup
C:\WINDOWS\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\tool1.exe -> TrojanDownloader.Small.bnt : Cleaned with backup
C:\WINDOWS\tool4.exe -> Trojan.Qhost.n : Cleaned with backup
C:\WINDOWS\tool5.exe -> Trojan.Qhost.n : Cleaned with backup
C:\WINDOWS\ms1.exe -> TrojanDropper.Microjoin : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OL2V4DA7\0006_adult[1].cab/istactivex.dll -> TrojanDownloader.IstBar.gu : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\09AZ8HYZ\installer[1].dll -> Spyware.Downloadware : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\09AZ8HYZ\0006_adult[1].cab/istactivex.dll -> TrojanDownloader.IstBar.gu : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr1474\SearchRelevancy1.dll -> Spyware.Relevance : Cleaned with backup
C:\Documents and Settings\Jakes\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Jakes\Application Data\Mozilla\Firefox\Profiles\xo4ye715.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Daves\Local Settings\Temp\3.exe -> TrojanSpy.Goldun.bf : Cleaned with backup
C:\Documents and Settings\Daves\Local Settings\Temp\dima2.exe -> TrojanDropper.Agent.py : Cleaned with backup
C:\Documents and Settings\Daves\Local Settings\Temp\tBmp207.exe -> Trojan.Crypt.l : Cleaned with backup
C:\Documents and Settings\Daves\Local Settings\Temp\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Daves\Local Settings\Temp\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Daves\Start Menu\Programs\SpySheriff -> Spyware.SpySheriff : Cleaned with backup
C:\Documents and Settings\Daves\Start Menu\Programs\SpySheriff\SpySheriff.lnk -> Spyware.SpySheriff : Cleaned with backup
C:\Documents and Settings\Cathy\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Cathy\Cookies\
[email protected][1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Cathy\Cookies\cathy@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Program Files\Internet Explorer\Iesearch.exe -> Backdoor.Zins : Cleaned with backup
C:\Program Files\SupaDial\SupaDial.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{8D7469A4-B487-48B9-8782-B05185F76186}\RP193\A0062466.EXE -> Backdoor.Wootbot : Cleaned with backup
C:\System Volume Information\_restore{8D7469A4-B487-48B9-8782-B05185F76186}\RP193\A0063502.dll -> Spyware.SpywareNo : Cleaned with backup
C:\System Volume Information\_restore{8D7469A4-B487-48B9-8782-B05185F76186}\RP193\A0063503.dll -> Adware.SpySheriff : Cleaned with backup
C:\System Volume Information\_restore{8D7469A4-B487-48B9-8782-B05185F76186}\RP193\A0063505.exe -> Adware.SpySheriff : Cleaned with backup
C:\Recycled\Dc8.exe -> Backdoor.Rbot : Cleaned with backup
C:\Recycled\Dc10.exe -> Backdoor.Agobot.nq : Cleaned with backup
C:\FOUND.003\FILE0001.CHK -> TrojanDownloader.Small.anu : Cleaned with backup
C:\users.exe -> TrojanProxy.Agent.co : Cleaned with backup
C:\crss.exe -> TrojanProxy.Agent.co : Cleaned with backup
::Report End
smitRem log file
version 2.6
by noahdfear
The current date is: 14/10/2005
The current time is: 16:59:50.45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
Pre-run Files Present
~~~ Program Files ~~~
SpySheriff
~~~ Shortcuts ~~~
SpySheriff
SpySheriff.lnk
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
desktop.html
~~~ Drive root ~~~
couldnt get the kasperspy one to work cus i have firefox as my default or something ... here are the rest though