Logfile of HijackThis v1.99.1
Scan saved at 5:10:33 PM, on 12/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\MacroMed\Flash\GetFlash.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Security Tools\ewido\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\0caff7z.exe
C:\WINDOWS\system32\0caff7z.exe
C:\WINDOWS\system32\0caff7z.exe
C:\WINDOWS\system32\0caff7z.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\0caff7z.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Security Tools\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://wapp.verizon....ie&bm=yh_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon....1_ie&bm=yh_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shawneelink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3} - C:\WINDOWS\SYSTEM32\ll0.dll
O2 - BHO: SDWin32 Class - {93B5DCF9-A91A-41E3-9AF5-DCCF5DF0DB77} - C:\WINDOWS\System32\orrbh.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O4 - HKLM\..\Run: [htageaa] C:\WINDOWS\System32\htageaa.exe
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunOnce: [hzqzfv9.exe] C:\WINDOWS\system32\hzqzfv9.exe /k
O4 - HKCU\..\Run: [msencode] C:\WINDOWS\System32\msencode.exe
O4 - HKCU\..\Run: [d3d8] C:\WINDOWS\System32\d3d8.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\System32\196_150_ni.exe
O4 - HKCU\..\Run: [197_150_ni_4] C:\WINDOWS\System32\197_150_ni_4.exe
O4 - HKCU\..\Run: [198_150_ni_3] C:\WINDOWS\System32\198_150_ni_3.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [hzqzfv9.exe] C:\WINDOWS\system32\hzqzfv9.exe /k
O4 - Global Startup: Instant Update Reminder.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {354A56A8-738A-4D48-817D-58F90B7EC0E6} - http://www.shawneelink.net/support/ (file missing) (HKCU)
O9 - Extra button: SLU - {48D8AF06-65C3-4ECF-82AD-DA1B4302BB08} - http://slu.shawneelink.net (file missing) (HKCU)
O9 - Extra button: User Area - {688D4C17-1B0A-4F2E-BEE5-177F0EE846F0} - http://www.shawneelink.net/users/ (file missing) (HKCU)
O12 - Plugin for .MOV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.shawneelink.net
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1103038930889
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Security Tools\ewido\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Security Tools\ewido\ewido anti-malware\ewidoguard.exe
O23 - Service: kbdal - Unknown owner - C:\WINDOWS\system32\kbdal.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
Also I did an Ewido scan and it came up with this.
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 5:03:49 PM, 12/20/2005
+ Report-Checksum: C83887D9
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E992732-295F-4987-8BE3-16FAC1639198} -> Spyware.FastFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{0F2A4ADC-DABF-4980-8DB4-19F67D7B1F95} -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{8992B6CA-B8C9-4AED-BF89-0A17F6296A06} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\VoiceIPDll.VoiceIPDllObj.1 -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtensi.1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension\CLSID -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension\CurVer -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Dsi -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\MaxSpeed -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22B9A67D-E689-44B6-B775-0E8FE84B4F9B} -> Spyware.Hijacker.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MirrorUnder -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpiderSidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UrlSidebar -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8F9FBEB8-D216-4d6c-8D21-513157E09C0D} -> Spyware.Maxspeed : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\VoiceIP -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-2014835873-598665437-431110056-1003\Software\Bundles -> Spyware.SecondThought : Cleaned with backup
HKU\S-1-5-21-2014835873-598665437-431110056-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{120E090D-9136-4B78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-21-2014835873-598665437-431110056-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22B9A67D-E689-44B6-B775-0E8FE84B4F9B} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-2014835873-598665437-431110056-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A78860C8-EE1A-46DF-A97F-E3E6D433E80B} -> Spyware.AdTomi : Cleaned with backup
HKU\S-1-5-21-2014835873-598665437-431110056-1003\Software\VoiceIP -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\VoiceIP -> Spyware.BetterInternet : Cleaned with backup
[1348] C:\WINDOWS\system32\test.bmp -> Trojan.Small : Error during cleaning
[1540] C:\WINDOWS\system32\kbdal.exe -> Downloader.Small : Cleaned with backup
[2904] C:\WINDOWS\System32\orrbh.dll -> Spyware.Adstart : Error during cleaning
[2036] C:\WINDOWS\system32\test.bmp -> Trojan.Small : Error during cleaning
C:\Documents and Settings\Owner\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0C.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\Owner\xNJSORKVYEY.exe -> Downloader.Agent.am : Cleaned with backup
C:\Documents and Settings\Owner\xPXMTSOPWQD.exe -> Downloader.Agent.am : Cleaned with backup
C:\Documents and Settings\Owner\xUSYTIYGHYI.exe -> Downloader.Agent.am : Cleaned with backup
C:\Program Files\IncrediFind -> Spyware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO -> Spyware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO\date.txt -> Spyware.Incredifind : Cleaned with backup
C:\Program Files\Lycos\IEagent\A_ClearSearch.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\Program Files\Lycos\IEagent\csAOLldr.exe -> Spyware.ClearSearch : Cleaned with backup
C:\Program Files\Lycos\IEagent\FNuninstaller.EXE -> Spyware.ClearSearch : Cleaned with backup
C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP102\A0067270.sys -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP102\A0067271.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP102\A0067272.sys -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP102\A0067275.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP102\A0067323.exe -> Dropper.SurfSide.a : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP75\A0055644.exe -> Downloader.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP79\A0059157.dll -> Downloader.Apropo.l : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP79\A0059158.exe -> Downloader.Apropo.l : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP79\A0059160.exe -> Downloader.Apropo.l : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP79\A0059161.dll -> Downloader.Apropo.l : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP79\A0059260.exe -> Downloader.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059474.sys -> Trojan.Kolweb.b : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059475.sys -> Trojan.Kolweb.b : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059476.exe -> Trojan.Delf.cf : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059477.dll -> Trojan.Kolweb.a : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059478.exe -> Trojan.Delf.cf : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059479.exe -> Trojan.Kolweb.b : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059485.exe -> Trojan.Kolweb.e : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0059489.dll -> Trojan.Kolweb.d : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP80\A0061820.exe -> Downloader.Agent.am : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065049.sys -> Trojan.Kolweb.e : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065050.dll -> Trojan.Kolweb.d : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065051.exe -> Trojan.Kolweb.e : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065052.exe -> Trojan.Delf.cf : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065053.sys -> Trojan.Kolweb.e : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP82\A0065054.exe -> Trojan.Delf.cf : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065255.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065256.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065258.dll -> Trojan.Kolweb.d : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065262.exe -> Trojan.Delf.cf : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065267.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP86\A0065268.exe -> Trojan.Kolweb.g : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP92\A0066885.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP93\A0066921.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP94\A0066957.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP95\A0066993.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP96\A0067029.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP97\A0067173.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\WINDOWS\aqadcup.exe -> Backdoor.Agent.co : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADBN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DENT1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FMND1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEAL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HEBE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HOGAR2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INSUR4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPR2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TV1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\VENUE1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WOMEN2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\istinstall_si.exe -> Downloader.Small.gl : Cleaned with backup
C:\WINDOWS\SYSTEM32\acctres2.exe -> Downloader.3746.A : Cleaned with backup
C:\WINDOWS\SYSTEM32\adolib32.dll -> Downloader.Qoologic.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\bH.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2802040113.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2804040128.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\bridge91.exe -> Spyware.IEDriver : Cleaned with backup
C:\WINDOWS\SYSTEM32\browser1.dll -> Downloader.3746.A : Cleaned with backup
C:\WINDOWS\SYSTEM32\calsdr.dll -> Downloader.Rameh.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\calsdr.exe -> Dropper.Small.ff : Cleaned with backup
C:\WINDOWS\SYSTEM32\Cnpgkn32.exe -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\kk[1].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\kk[2].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\kk[3].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\kk[4].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\x[1].exe -> Worm.Padobot.m : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0LYB8PAR\x[2].exe -> Worm.Padobot.m : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[1].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[2].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[3].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[4].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[5].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[6].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\kk[7].gif -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C8A72ME5\x[1].exe -> Worm.Padobot.m : Cleaned with backup
C:\WINDOWS\SYSTEM32\cvss.exe -> Downloader.Qoologic.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\Fofeef32.dll -> Backdoor.Padodor.v : Cleaned with backup
C:\WINDOWS\SYSTEM32\Fqr9U5uF.exe -> Downloader.VB.em : Cleaned with backup
C:\WINDOWS\SYSTEM32\ftpupd.exe -> Worm.Padobot.m : Cleaned with backup
C:\WINDOWS\SYSTEM32\hbahead.exe -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hhidegn.dll -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hjbtq.exe -> Worm.Padobot.m : Cleaned with backup
C:\WINDOWS\SYSTEM32\hjifeer.sys -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hjiryfj.vxd -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hkageel.sys -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hmiwycr.exe -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hoaiyfr.vxd -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hpipebn.exe -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\hraieba.exe -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\huauycp.exe -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\huiwegf.dll -> Trojan.Painwin.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\id113.exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\WINDOWS\SYSTEM32\in10b6s.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\in10bH.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\istinstall_143666.exe -> Downloader.IstBar.er : Cleaned with backup
C:\WINDOWS\SYSTEM32\jpdwuf.exe -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\K404SearchSetup_MS18.exe -> Spyware.404Search : Cleaned with backup
C:\WINDOWS\SYSTEM32\kbdal.exe -> Downloader.Small : Cleaned with backup
C:\WINDOWS\SYSTEM32\kbdcz.exe -> Trojan.Downloader.reqlook : Cleaned with backup
C:\WINDOWS\SYSTEM32\Lkofhn32.exe -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\mirka3e.exe -> Trojan.Delf.cf : Cleaned with backup
C:\WINDOWS\SYSTEM32\Mjapgh32.dll -> Backdoor.Padodor.v : Cleaned with backup
C:\WINDOWS\SYSTEM32\ms.exe -> Downloader.Vb.Cw : Cleaned with backup
C:\WINDOWS\SYSTEM32\orrbhc.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\SYSTEM32\orrbhf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\SYSTEM32\scxggb.exe -> Logger.Qukart : Cleaned with backup
C:\WINDOWS\SYSTEM32\Searchx.htm -> Spyware.TwainTech : Cleaned with backup
C:\WINDOWS\SYSTEM32\stubwinx.exe -> Spyware.IEDriver : Cleaned with backup
C:\WINDOWS\SYSTEM32\SWRT01.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\SYSTEM32\ui3.dll -> Trojan.Kolweb.f : Cleaned with backup
C:\WINDOWS\SYSTEM32\Wlsb9SH.exe -> Downloader.VB.em : Cleaned with backup
C:\WINDOWS\SYSTEM32\xCTSBWGVPFK.exe -> Downloader.Agent.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\xKYYCPNNAJP.exe -> Downloader.Agent.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\xLYEXWNJHAD.exe -> Downloader.Agent.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\xRIVVUUNIUS.exe -> Downloader.Agent.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__198_150_ni_3.exe -> Downloader.Agent.am : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__orrbh.dll -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__test.bmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\Temp\~499301.tmp -> Downloader.WinTool : Error during cleaning
C:\WINDOWS\Temp\~778905.tmp -> Downloader.WinTool : Error during cleaning
C:\WINDOWS\Temp\~892989.tmp -> Downloader.WinTool : Error during cleaning
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
::Report End
Thanks.