This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Would like help removing Aurora ABI Virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Am trying to remove that pesky Aurora ABI Virus. Have run Spybot S&D and Ad-Aware. Here is my HJT Log…

Logfile of HijackThis v1.99.1
Scan saved at 12:29:06 AM, on 8/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\dinst.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINDOWS\System32\wuauclt.exe
C:\My Download Files\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\UTILIT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [Hot Video] C:\WINDOWS\System32\ShellExt\CNTR.EXE -n
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [gaglgkc] c:\windows\system32\fdtmqnb.exe r
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax3028.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

First, download Ewido Security Suite.

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in. Install Ad-Aware using the default options, then unzip the VX2 plugin to the directory C:\Program Files\Lavasoft\Ad-Aware SE Personal\Plugins. There should be two files in the Plugins directory called "vx2cleaner.dll" and "vx2cleaner.dlx" when properly installed.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.
Everything ran, except that I was never prompted to set Ad-Aware to run on reboot, so I did not do that. Otherwise, here is my HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 11:24:30 PM, on 8/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\wuauclt.exe
C:\My Download Files\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\UTILIT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [Hot Video] C:\WINDOWS\System32\ShellExt\CNTR.EXE -n
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax3028.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

******************************************************************

Here is my ewido scan…

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 11:20:42 PM, 8/23/2005
+ Report-Checksum: D441F833

+ Scan result:

[3084] C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Ashley\Application Data\Symantec\Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Symantec\Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Macromedia\Flash Player\#SharedObjects\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Application Data\Symantec\Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\donna@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\donna@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\donna@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\Donna\Cookies\[removed][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Macromedia\Flash Player\#SharedObjects\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Application Data\Symantec\Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Garrett\Cookies\garrett@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Application Data\Symantec\Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Jeff\Local Settings\Temp\temp.fr12EF -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\3EW3ZT0T\banner[1].cab/banner.dll -> Spyware.Banex : Cleaned with backup
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\AX47YDA5\abiuninst[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\SDSFSZKF\Poller[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\locales\en_us\getting_started\quick_guide\share\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Adobe\Photoshop Album Starter Edition\2.0\Shared_Assets\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Adaptec Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Works Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Common Files\Symantec Shared\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Creative\ShareDLL\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Opera 8 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Porno pics arhive, xxx.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Porno Screensaver.scr -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Porno, sex, oral, anal cool, awesome!!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Serials.txt.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\WinAmp 5 Pro Keygen Crack Update.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\WinAmp 6 New!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Windown Longhorn Beta Leak.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\Windows Sourcecode update.doc.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\Kazaa\My Shared Folder\XXX hardcore images.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\ACDSee 9.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Adobe Photoshop 9 fuââ.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Ahead Nero 7.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Kaspersky Antivirus 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\KAV 5.0 -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Matrix 3 Revolution English Subtitles.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Microsoft Office 2003 Crack, Working!.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Microsoft Office XP working Crack, Keygen.exe -> Worm.Bagle.au : Cleaned with backup
C:\Program Files\McAfee.com\Shared\Microsoft Windows XP, WinXP Crack, working Keygen.exe -> W
Click here, for instructions on how to enable hidden files and folders to be visible. After enabling, find, zip and send this file:

C:\WINDOWS\System32\ShellExt\CNTR.EXE

to this e-mail address including a link to this thread in the body of the email.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O4 - HKLM\..\Run: [Hot Video] C:\WINDOWS\System32\ShellExt\CNTR.EXE -n
O4 - Startup: PowerReg Scheduler.exe


Exit HijackThis when done. Reboot, rescan with HijackThis and post a new log here.
Final HJT Log…

Logfile of HijackThis v1.99.1
Scan saved at 10:26:52 PM, on 8/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\wuauclt.exe
C:\My Download Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\UTILIT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax3028.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI