I've run Adaware, MS Beta, CWS Shredder, Ewido... All of which achieved something - Ewido most recently giving the log down below...
Still getting a few errors and a redirect to a page ending in "yyy102.html"
I've got a HJT log and I'll post the Ewido log from tonight as well - but if anyone has any suggestions - I'd really appreciate it.
There's a UCMore folder under C:\ that I'm sure I've deleted before - and an "install.bat" file in C:\ that has commands to start eula.htm and thanks.exe... (I think Ewido may have gotten rid of those files though)
Here's my HJT log...
Logfile of HijackThis v1.99.1
Scan saved at 11:56:46 PM, on 26/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Telstra\Cable Login\bpcable.exe
C:\WINDOWS\Servces32.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\HJT\HijackThis.exe
O1 - Hosts: 216.180.239.154 www.halifax-online.co.uk
O1 - Hosts: 216.180.239.154 ibank.barclays.co.uk
O1 - Hosts: 216.180.239.154 online.lloydstsb.co.uk
O1 - Hosts: 216.180.239.154 online-business.lloydstsb.co.uk
O1 - Hosts: 216.180.239.154 www.ukpersonal.hsbc.co.uk
O1 - Hosts: 216.180.239.154 www.nwolb.com
O1 - Hosts: 216.180.239.154 banesnet.banesto.es
O1 - Hosts: 216.180.239.154 extranet.banesto.es
O1 - Hosts: 216.180.239.154 ebanking.bccbrescia.it
O1 - Hosts: 216.180.239.154 www.bankofscotlandhalifax-online.co.uk
O1 - Hosts: 216.180.239.154 www.rbsdigital.com
O1 - Hosts: 216.180.239.154 oi.cajamadrid.es
O1 - Hosts: 216.180.239.154 bancae.caixapenedes.com
O1 - Hosts: 216.180.239.154 banking.postbank.de
O1 - Hosts: 216.180.239.154 meine.deutsche-bank.de
O1 - Hosts: 216.180.239.154 myonlineaccounts2.abbeynational.co.uk
O1 - Hosts: 216.180.239.154 ibank.cahoot.com
O1 - Hosts: 216.180.239.154 webbank.openplan.co.uk
O1 - Hosts: ound.net
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\yaywt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BigPondCable] "C:\Program Files\Telstra\Cable Login\bpcable.exe" /r
O4 - HKLM\..\Run: [Windows Services] C:\WINDOWS\Servces32.exe
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1130580841373
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1131974354811
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\lv4409hqe.dll
O20 - Winlogon Notify: yaywt - C:\WINDOWS\SYSTEM32\yaywt.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BigPond Broadband Cable Login (bpcService) - Unknown owner - C:\Program Files\Telstra\Cable Login\bpcService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0dA\command.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
and EWIDO:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:11:31 PM, 26/11/2005
+ Report-Checksum: 66D34A1E
+ Scan result:
[308] C:\WINDOWS\system32\olbc32.dll -> Spyware.Look2Me : Error during cleaning
[680] C:\WINDOWS\system32\olbc32.dll -> Spyware.Look2Me : Error during cleaning
[1360] C:\windows\adtech2005.exe -> Trojan.VB.afn : Cleaned with backup
[2064] C:\WINDOWS\system32\msniq.exe -> Backdoor.Rbot : Cleaned with backup
C:\31t.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
:mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.18:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.19:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.20:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.21:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.34:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.49:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.51:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\0kiw0btt.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01K3DW6G\mte3ndi6odoxng[1].exe -> TrojanDownloader.Small.buy : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01K3DW6G\picture_22[1].com -> Backdoor.Rbot : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DH3MEI1Q\thanks[1].exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DH3MEI1Q\timessquare[1].exe -> Spyware.Hijacker.StartPage.aw : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\EXAWR483\mg[1].exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\EXAWR483\thanks[1].exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FSB9GH0M\adtech2005[1].exe -> Trojan.VB.afn : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FSB9GH0M\drsmartload[1].exe -> Spyware.SmartLoad : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FSB9GH0M\installer[1].exe -> Spyware.Look2Me : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\xwzxezt0.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Matt\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Matt\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\393834_11684_2704_11728_78.41.tmp -> Trojan.EliteBar.g : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\k_3F08.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\k_7769.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\Temporary Internet Files\Content.IE5\40OTURA6\thanks[1].exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temp\Temporary Internet Files\Content.IE5\5A7QMW6L\mg[1].exe -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\RS2CMWFY\AppWrap[1].exe -> Spyware.Zestyfind : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\XGZIAK3D\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\XGZIAK3D\silent_setup[1].exe -> TrojanDropper.Agent.za : Cleaned with backup
C:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\ZI1KLVN6\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\drsmartload1.exe -> Spyware.SmartLoad : Cleaned with backup
C:\installer.exe -> Spyware.Look2Me : Cleaned with backup
C:\m1t.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\m31g.exe -> Backdoor.Rbot : Cleaned with backup
C:\m31t.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\mg.exe -> Spyware.WinAD : Cleaned with backup
C:\mte3ndi6odoxng.exe -> TrojanDownloader.Small.buy : Cleaned with backup
C:\Program Files\Common Files\orrr\orrra.exe -> TrojanDownloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\orrr\orrrm.exe -> TrojanDownloader.TSUpdate.n : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0ADA4393-496B-4D03-920B-015C20\A0570CC9-A6C4-48DC-8B88-EA2924 -> Adware.CommAd : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0005097.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0005103.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0005106.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0005113.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0005114.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006108.dll -> Trojan.EliteBar.g : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006114.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006115.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006116.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006123.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006124.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006126.dll -> Trojan.EliteBar.g : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006132.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006133.exe -> TrojanDropper.Agent.za : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006134.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006135.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006142.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006145.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0006146.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0007142.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP14\A0007145.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP15\A0007173.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP18\A0007256.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP18\A0007276.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP18\A0007277.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP18\A0007282.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP18\A0007285.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP24\A0007479.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007674.dll -> Trojan.EliteBar.g : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007693.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007834.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007843.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007845.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007856.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007862.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007871.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007877.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007887.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007890.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007906.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007913.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007918.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007921.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0007994.dll -> Trojan.EliteBar.g : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008001.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008002.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008003.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008006.dll -> Trojan.EliteBar.g : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008011.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008014.exe -> Spyware.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008015.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008019.dll -> Trojan.EliteBar.h : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008020.exe -> Trojan.EliteBar : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008026.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008028.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008047.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008052.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008053.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008063.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008066.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008073.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008074.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008084.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008085.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008094.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008095.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008104.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP27\A0008106.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP28\A0008119.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP28\A0008120.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP28\A0008140.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP28\A0008142.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008167.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008169.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008175.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008177.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008182.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP29\A0008185.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008194.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008195.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008203.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008205.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008211.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008212.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008224.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008226.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008241.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008245.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008254.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008256.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008267.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP30\A0008271.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008279.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008281.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008291.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008293.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008304.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008306.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008311.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008315.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008323.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008325.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008330.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP31\A0008332.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP32\A0008339.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP32\A0008341.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008386.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008388.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008394.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008396.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008402.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP34\A0008404.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP35\A0008780.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP35\A0008782.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP35\A0008811.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP35\A0008812.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008918.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008920.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008925.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008927.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008932.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP36\A0008934.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008943.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008948.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008949.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008951.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008955.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008957.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008958.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008959.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0008961.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP37\A0009118.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009289.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009290.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009334.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009335.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009336.exe -> Backdoor.Rbot : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009337.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009338.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009340.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP39\A0009341.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012442.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012447.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012468.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012476.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012481.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0012485.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0013485.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0013492.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0013497.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0013500.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014497.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014500.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014502.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014506.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014508.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014512.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014516.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014518.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014520.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014525.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP41\A0014526.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014534.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014538.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014540.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014547.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014551.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014553.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014566.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014570.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014572.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014581.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014585.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014587.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014610.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014615.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014616.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014624.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014628.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014630.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014632.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014636.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP42\A0014638.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014640.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014644.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014646.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014648.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014652.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014654.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014657.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014661.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014663.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014665.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014669.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014672.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014684.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014688.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014690.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014707.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014711.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP43\A0014713.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014715.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014719.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014721.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014727.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014731.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014733.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014738.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014742.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014744.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014767.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014771.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014773.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014786.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014790.sys -> Trojan.Rootkit.k : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014793.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014795.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014797.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014798.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014800.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014803.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014808.bat -> Trojan.Zapchast : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014809.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014810.exe/thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014812.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014814.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014815.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{DBEEC43F-1F58-49C3-A089-09F1DA3D9397}\RP44\A0014817.exe -> Spyware.Zestyfind : Cleaned with backup
C:\thanks.exe -> TrojanDownloader.VB.qr : Cleaned with backup
C:\WINDOWS\adtech2005.exe -> Trojan.VB.afn : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\iconu.exe -> Spyware.Zestyfind : Cleaned with backup
C:\WINDOWS\system32\apiiiexx.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\aydiosrv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\bvtsprx2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ckiconfg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dqkquota.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dYd8.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dzrgui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\g4220efoeh2c0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\h8n00i5me8.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kadycc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kldbr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kndmlt48.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kudir.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOW