I managed to get EWIDO started..
cleaned lots of stuff..
here is the report
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 00:03:37, 19/03/2006
+ Report-Checksum: 93BF351D
+ Scan result:
[236] C:\WINDOWS\System32\csrssv.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\IZ43YZ83\drsmartload[1].exe -> Downloader.Adload.x : Cleaned with backup
C:\WINDOWS\system32\csrssv.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\system32\LogFiles\A5051800.so -> Trojan.LowZones.ba : Cleaned with backup
C:\WINDOWS\system32\logon.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\system32\lgwbuye.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\system32\pmsdwikt.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\system32\winscntrl.exe -> Trojan.Pakes : Cleaned with backup
C:\WINDOWS\system32\uwmhmp.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\system32\bgeydinx.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS\system32\nmafamvs.exe -> Backdoor.Rbot.apd : Cleaned with backup
C:\WINDOWS\tok\smart.exe -> Downloader.Adload.t : Cleaned with backup
C:\WINDOWS\cn.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\WINDOWS\mm83.ocx -> Downloader.VB.ov : Cleaned with backup
C:\WINDOWS\eltpower.exe -> Logger.Agent.hi : Cleaned with backup
C:\WINDOWS\spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\WINDOWS\spool\newdr.exe -> Downloader.Adload.t : Cleaned with backup
C:\WINDOWS\pi1_34.exe -> Downloader.Small.bue : Cleaned with backup
C:\WINDOWS\surv3.exe -> Downloader.VB.vv : Cleaned with backup
C:\WINDOWS\876057.exe -> Adware.Mirar : Cleaned with backup
C:\WINDOWS\876029.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\cm\index.exe -> Hijacker.Small.hh : Cleaned with backup
C:\WINDOWS\cm\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\WINDOWS\cm\newdr.exe -> Downloader.Adload.t : Cleaned with backup
C:\WINDOWS\elitemediapop.exe -> Trojan.LowZones.am : Cleaned with backup
C:\WINDOWS\inst_adperform.exe -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\winhost32.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[1].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[2].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[3].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[4].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[5].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[6].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[7].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[8].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[9].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[10].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[11].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[12].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[13].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GDAJS12B\sysdat[14].exe -> Proxy.Ranky.ek : Cleaned with backup
C:\Documents and Settings\Mario&Josette\Local Settings\Temp\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Mario&Josette\My Documents\Pictures\Josette\Anti-virus programs\backups\backup-20060317-143327-927.dll -> Adware.E2Give : Cleaned with backup
C:\Documents and Settings\Mario&Josette\My Documents\Pictures\Josette\Anti-virus programs\backups\backup-20060317-144006-557.dll -> Adware.Mirar : Cleaned with backup
C:\Documents and Settings\Mario&Josette\Cookies\mario&josette@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Mario&Josette\bleh.exe -> Dropper.Agent.ye : Cleaned with backup
C:\Program Files\Common Files\System\Mapi\1033\bleh.exe -> Dropper.Agent.ye : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\VVSN\VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Save -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Save\SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\mousepad2.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP233\A0046752.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP233\A0046754.EXE -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP233\A0046756.DLL -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0049379.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0049380.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050371.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050375.exe -> Downloader.Small.buy : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050412.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050423.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050424.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0050425.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051397.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051398.exe -> Logger.VB.eh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051401.exe/spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051401.exe/spool\is940.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051402.exe -> Downloader.Small.bue : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051403.exe -> Adware.Mirar : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051404.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051405.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051406.exe -> Downloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051455.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051465.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051466.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051467.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051479.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051480.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051482.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051485.exe -> Trojan.Scapur.k : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052589.exe -> Logger.VB.eh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051491.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051562.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051563.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051564.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051565.exe/spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051565.exe/spool\is940.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051566.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051567.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051569.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051572.exe -> Trojan.Scapur.k : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051574.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051580.exe -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051581.exe -> Downloader.PurityScan.br : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051587.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051589.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051592.exe/spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051592.exe/spool\is940.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051593.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051594.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051596.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051597.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051600.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051603.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051604.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051606.exe -> Downloader.Small.bue : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051607.exe -> Downloader.VB.vv : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051608.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051610.exe -> Logger.VB.eh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0051614.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052591.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052595.exe/spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052595.exe/spool\is940.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052599.exe -> Downloader.Small.bue : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052600.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052601.exe/eee2.exe -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052602.exe -> Downloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052604.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052606.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052607.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0052609.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053587.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053665.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053667.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053670.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053671.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0053673.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054588.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054589.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054591.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054599.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054600.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054602.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054608.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054609.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054610.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054611.ocx -> Downloader.VB.ov : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054612.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054615.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054616.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054618.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054626.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054627.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054632.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054636.exe/spool\index1.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054636.exe/spool\is940.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054723.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054724.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054725.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0054726.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055626.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055699.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055701.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055704.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055705.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0055707.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0056626.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0056627.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0056633.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0056636.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0057629.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0057630.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0057632.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0057636.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0059634.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0058631.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0058632.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0058634.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0058640.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0058641.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061718.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0059635.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0059639.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0059643.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0059644.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061719.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060631.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060632.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060634.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060637.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060638.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060643.exe -> Trojan.Scapur.k : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060645.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060646.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061720.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060652.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060654.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060663.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060664.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060666.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060676.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060678.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060681.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060685.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060686.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060688.exe -> Logger.Agent.hi : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060689.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060690.exe -> Hijacker.Small.hh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060691.exe -> Trojan.LowZones.cf : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060693.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060698.exe -> Trojan.Scapur.k : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060700.ocx -> Adware.MediaMotor : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060707.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060708.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060719.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060720.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060721.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060722.exe -> Downloader.VB.yn : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060727.exe -> Downloader.VB.jl : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060728.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060730.exe -> Downloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060731.exe -> Adware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060776.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0060778.dll -> Adware.Mirar : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061673.exe -> Backdoor.Small.eo : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061711.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061714.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061726.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061727.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061729.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061732.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061735.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0061736.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062731.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062732.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062734.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062756.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062757.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062759.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062762.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062778.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062779.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062781.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0062784.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063790.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063791.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063795.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063798.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063813.exe/smart.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063817.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063818.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063821.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063828.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063829.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063832.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063846.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063847.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063848.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063854.exe -> Downloader.Adload.t : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063859.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063860.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063864.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063869.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063873.dll -> Adware.E2Give : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063877.exe -> Backdoor.Rbot.asp : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063880.dll -> Adware.Mirar : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0063883.exe -> Logger.VB.eh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066911.dll -> Adware.Mirar : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066912.exe -> Logger.VB.eh : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066913.exe -> Downloader.PurityScan.br : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066914.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066915.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066916.dll -> Adware.Softomate : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP250\A0066917.exe -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0069918.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0070899.EXE -> Dropper.Agent.ye : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0079011.exe -> Adware.Virtumonde : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0079070.exe -> Trojan.Scapur.k : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0079097.exe -> Dropper.Agent.aac : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0079099.exe -> Adware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{451C02A7-B37D-481A-95AA-19FAF2A06CCC}\RP251\A0079101.exe -> Dropper.Agent.aac : Cleaned with backup
C:\a.bat -> Trojan.Zapchast : Cleaned with backup
::Report End
and the HJT
Logfile of HijackThis v1.99.1
Scan saved at 00:13:26, on 19/03/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\BENQMA~1\QtEiBenQ.EXE
C:\Program Files\O2Micro\SuperDJ\o2mdj.exe
C:\Program Files\BenQ\QMusic\QMAgent.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mario&Josette\My Documents\Pictures\Josette\Anti-virus programs\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.repubblica.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.repubblica.it/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.benq.com/
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.en-us.en-gb\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QtEiBenQ] C:\PROGRA~1\BENQMA~1\QtEiBenQ.EXE
O4 - HKLM\..\Run: [o2cd] C:\Program Files\O2Micro\SuperDJ\o2mdj.exe
O4 - HKLM\..\Run: [QMusic] "C:\Program Files\BenQ\QMusic\QMAgent.exe"
O4 - HKLM\..\Run: [Ulead Memory Card Detector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://WWW.BenQ.COM/
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.c..._1/yregucfg.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{52994B03-1651-4E02-921A-36DB03AB21F8}: NameServer = 83.146.21.5 212.158.248.6
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: wins(WINS) (wins) - Unknown owner - C:\WINDOWS\system32\winscntrl.exe (file missing)
THANKS