Ken,
These entries were not found to delete in the hijack this log:
O2 - BHO: (no name) - {C7CF1142-0785-4B12-A280-B64681E4D45E} - C:\WINDOWS\prflbmsgp32.dll
O2 - BHO: (no name) - {CB4697C2-0A72-46F8-9AF4-EE648F3E92A7} - C:\WINDOWS\apigs.dll (file
missing)
O4 - HKLM\..\Run: [vmlib] vmlib.exe
O23 - Service: Network Security Service (NSS) (%AF夶À¨) - Unknown owner -
C:\WINDOWS\system32\netll.exe (file missing)
also when searching for the files in red i was only able to find 3 files. Two of them related to the cc.exe (one i believe was cc.exe and another contained some cc.exe type wording and i deleted it too.) I also found a file called __delete_on_reboot__st3.dll but did not delete it.
I ran the cwshredder and ewido.
panda and housecall both found a whole bunch of stuff...
here are the logs:
panda
Incident Status Location
Spyware:spyware/smitfraud Not disinfected C:\WINDOWS\SYSTEM32\oleext32.dll
Adware:adware/psguard Not disinfected C:\WINDOWS\warnhp.html
Spyware:spyware/searchcentrix Not disinfected Windows Registry
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Brian Hanson\Cookies\brian hanson@doubleclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Brian Hanson\Cookies\brian hanson@mediaplex[2].txt
Spyware:Cookie/Abcsearch Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt[.abcsearch.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt[.ask.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt[.maxserving.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.zedo.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.go.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.tickle.com/]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.ct.360i.com/]
Spyware:Cookie/Abcsearch Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.abcsearch.com/]
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[.ask.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt[]
Spyware:Cookie/Abcsearch Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt[]
Virus:Trj/ClassLoader.U Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-6a0390d7-47949aa1.zip[BlackBox.class]
Virus:Trj/ClassLoader.V Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-6a0390d7-47949aa1.zip[VB.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-6a0390d7-47949aa1.zip[Dummy.class]
Virus:Trj/Downloader.HAS Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-6a0390d7-47949aa1.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-1910af14-6f234e12.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-1910af14-6f234e12.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-1910af14-6f234e12.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-1910af14-6f234e12.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-76935f99-22c00d7d.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-76935f99-22c00d7d.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-76935f99-22c00d7d.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-76935f99-22c00d7d.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-c7acf92-1f6844a4.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-c7acf92-1f6844a4.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-c7acf92-1f6844a4.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-c7acf92-1f6844a4.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-652b4e66-3eb36219.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-652b4e66-3eb36219.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-652b4e66-3eb36219.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-652b4e66-3eb36219.zip[Beyond.class]
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-44a7c557.zip[InstallerApplet.class]
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Brian Hanson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-3eea367f.zip[InstallerApplet.class]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Brian Hanson\Cookies\brian hanson@doubleclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Brian Hanson\Cookies\brian hanson@mediaplex[2].txt
Adware:Adware/Miamore Not disinfected C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\7HR1KU4W\adsldpbd[1].dll
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\JAOVRPWT\connect[1][Content]
Potentially unwanted tool:Application/ServUBased.A Not disinfected C:\Serv-U\ServUDaemon.exe
Potentially unwanted tool:Application/ServUBased.A Not disinfected C:\Stuff\Saved Installs\susetup.exe[SERVUDAEMON.EXE]
Adware:Adware/Miamore Not disinfected C:\WINDOWS\cpblpbc3.log
Adware:Adware/SearchAid Not disinfected C:\WINDOWS\javaqv.exe
Virus:W32/Spybot.gen.worm Disinfected C:\WINDOWS\SYSTEM32\coca.exe
Virus:W32/Smitfraud.D Disinfected C:\WINDOWS\SYSTEM32\oleext32.dll
Adware:Adware/Miamore Not disinfected C:\WINDOWS\SYSTEM32\__delete_on_reboot__st3.dll
Virus:Trj/HideProc.B Disinfected C:\WINDOWS\Temp\1.tmp
Spyware:Spyware/Smitfraud Not disinfected C:\WINDOWS\warnhp.html
Ewido
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:33:19 PM, 1/7/2006
+ Report-Checksum: E1D48279
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{0E37D9E0-99E3-DA14-3197-60132338963E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2402BAD1-2B03-B117-D0E4-9685436E0914} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{33DA09FC-0D84-29B4-815F-CC48795929D4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{37E5E66E-C168-B55B-BE2E-8478ED77CD96} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{46B118F7-A9C3-30B6-F02A-A8C72E1E4FD5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{483C767C-E381-7083-FD10-379897AEDEFB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4992E461-38DD-211A-FDE8-64A8C67647AD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5AECFEAF-B010-FBFD-B79E-285458AE4BFB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5E7CC15F-6447-9E5E-1684-8AFEB8203457} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{602C9652-36AF-DEC5-DE23-DB34295B6BA5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{66F47DB1-18C4-9337-E85F-30B8B1DD594A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6916E12D-B7B5-E5B2-A230-80E344B0872D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{74339574-CCF2-3651-E5EA-88C8BFBBFB28} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{77E35B59-5DBF-CA0F-2037-00B52E21E874} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{83F01EC6-1966-280C-39C0-52CF1BB626F6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{87647AF0-CDBF-C0AC-94F6-54F97CE2A6CA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8DFCBD6E-113A-2348-6A3E-397AD2C21017} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9131706F-D034-5F4E-62F6-C060F737064C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9261C8D3-6127-C95A-7B9B-F9E8EE283C42} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9436A461-8EBA-8CCA-C8D5-98D6F786767A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9564CC48-05D0-7649-4D33-CBDCCFF9913B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E960055-CBAB-522C-F6D0-3C06FAA39285} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9F97B6E9-C174-2E0C-BAF8-5BB263486A64} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A229042B-0D56-44A6-85DB-13CF1C4E9FD6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A5910E94-A676-201D-0838-F81C7746194D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B536A5F4-6F9B-5215-B3D9-716EF3F258A6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C7339624-BDA9-0FBB-8706-46F6CC80401F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D036544E-A9A9-5899-2551-5FC716B1F4E2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E7081361-B49F-D230-D56A-D49C0144CDBE} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EAE338CA-76EC-EAE9-7C17-A152A831A537} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EFFA5234-1603-4600-4D31-8FE60DB658FB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F4BF9913-CC48-121B-F8DE-11BD3C45410F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
[232] C:\WINDOWS\system32\st3.dll -> Downloader.Delf.h : Cleaned with backup
[760] C:\WINDOWS\system32\st3.dll -> Downloader.Delf.h : Error during cleaning
:mozilla.14:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.374:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.398:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.435:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.436:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.438:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.446:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.447:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Firefox\Profiles\scwvt6d8.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Brian Hanson\Application Data\Mozilla\Profiles\default\0gbhy1fx.slt\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\ablgopmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\cmcnjpmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\emnmjpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\ifdhjpmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\mihajpmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\mmjmjpmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\njomjpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temp\onemjpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\25TIZQTG\gdnUS2161[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\7HR1KU4W\adsldpbe[2].dll -> Downloader.Delf.lh : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\912CDNOP\gdnUS2161[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\912CDNOP\pic[1].wmf -> Exploit.MS05-053-WMF : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\912CDNOP\psg[1].anr -> Downloader.Ani.c : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\912CDNOP\st3m[1].dll -> Downloader.Delf.h : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\JAOVRPWT\pic[1].wmf -> Exploit.MS05-053-WMF : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\WJL36AJH\alt[1].exe -> Hijacker.Delf.eb : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\WJL36AJH\load4[1] -> Downloader.Small.byk : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\XP8RS23V\prflbmsgp32_se[1].dll -> Downloader.Delf.yb : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\XP8RS23V\US[1].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\Z9S23MWX\adsldpbf[13].dll -> Downloader.Delf.lh : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\Z9S23MWX\gdnUS2161[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\Z9S23MWX\gdnUS2175[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\Z9S23MWX\load4[1] -> Downloader.Small.byk : Cleaned with backup
C:\Documents and Settings\Brian Hanson\Local Settings\Temporary Internet Files\Content.IE5\Z9S23MWX\runapl[1].exe -> Trojan.Small.ev : Cleaned with backup
C:\ntdetecd.exe -> Trojan.LowZones.cu : Cleaned with backup
C:\ntps.exe -> Trojan.Small.ev : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107304.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107305.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107306.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107307.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107308.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107309.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107310.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107311.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107312.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107313.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107314.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107315.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1121\A0107316.dll -> Downloader.Delf.lh : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1135\A0110024.dll -> Adware.PSGuard : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1135\A0110029.exe -> Adware.PSGuard : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1137\A0111269.dll -> Downloader.Delf.zu : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1137\A0111270.dll -> Downloader.Delf.zu : Cleaned with backup
C:\WINDOWS\adsldpbf.dll -> Downloader.Delf.lh : Cleaned with backup
C:\WINDOWS\alt.exe -> Hijacker.Delf.eb : Cleaned with backup
C:\WINDOWS\appig32.dll -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bgdzmg.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\BOOTSTAT.DAT:lerhn -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\byunhh.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\cfrxsb.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\COMSETUP.LOG:ftqce -> Downloader.Agent.cd : Cleaned with backup
C:\WINDOWS\cpblpbc5.log -> Downloader.Delf.lh : Cleaned with backup
C:\WINDOWS\crzv32.dll -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cvrzsp.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnUS2161.exe -> Downloader.Small.ayl : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gsda.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\edagug.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\EXPLORER.EXE:nkoks -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:ydgpu -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\javaqv.exe:kvvfd -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\KB823559.log:cwosf -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\KB837001.log:mgxun -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB840315.log:whqzh -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\khqkfk.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\lkrxui.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\mgupby.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\mnedun.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\msoffice.ini:kxrhk -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msuh32.dll -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mswk.dll -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\muninst.exe:cycnm -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\netcy.dll -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NOTEPAD.EXE:cpgve -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\n_bqpvfv.dat -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\n_dvcqfq.txt -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\n_hsdvjd.dat -> Downloader.Agent.gs : Cleaned with backup
C:\WINDOWS\n_ifpuod.dat:hrafc -> Downloader.Agent.cd : Cleaned with backup
C:\WINDOWS\n_ifpuod.dat -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_jquozh.dat -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_pqtjvs.dat -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\pfpxdk.dat -> Downloader.Agent.al : Cleaned with backup
C:\WINDOWS\playenu.hlp:mwuja -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\PowerReg.dat:knvpp -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:fpmxu -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:wvsrq -> Downloader.Agent.bq : Cleaned with backup
C:\WINDOWS\prflbmsgp32.dll -> Downloader.Delf.yb : Cleaned with backup
C:\WINDOWS\PSDELUXE.ICO:cofuj -> Downloader.Agent.cd : Cleaned with backup
C:\WINDOWS\Q323255.log:pvlwt -> Downloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Q328213.log:rzpbt ->
Edited by caffeinated, 08 January 2006 - 02:38 AM.