Ok. Completed that scan. Here is the new Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 3:22:38 PM, on 12/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wpabaln.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\system32\PROMon.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\WINDOWS\system32\mwinosap.exe
C:\WINDOWS\SYS99.exe
C:\WINDOWS\ms03794031744.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\sf\sf.exe
C:\WINDOWS\system32\mwinosap.exe
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F3 - REG:win.ini: run=C:\WINDOWS\inet20003\services.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [04ug00pk.dll] RUNDLL32.EXE 04ug00pk.dll,b 9778843
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [Jumbo Updater] C:\WINDOWS\System32\jumb.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\mwinosap.exe CORN001
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\msbk32.dll,DllRun
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYS99.exe
O4 - HKLM\..\Run: [ms03794031744] C:\WINDOWS\ms03794031744.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
O4 - HKCU\..\Run: [qfow] C:\PROGRA~1\COMMON~1\qfow\qfowm.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\mwinosap.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1135996349374
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -
http://www.trendmicr...scan/as4web.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn...ro.cab34246.cab
O20 - Winlogon Notify: Hints - C:\WINDOWS\system32\k8jsli1718.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\SmFtZXM\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
Here is the ewido log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 1:51:24 PM, 12/31/2005
+ Report-Checksum: 36CF09A7
+ Scan result:
HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension.5 -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\drs.n -> Adware.Searchforit : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Keywords -> Spyware.CoolWebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp\sfitb -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp\sfitb\161 -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp\sfitb\74 -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp\sfitb\76 -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\DR_S\dp\ts -> Adware.Searchforit : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\Microsoft\Internet Explorer\Keywords -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1993962763-484061587-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Keywords -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Cleaned with backup
[1772] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[1824] c:\program files\common files\microsoft shared\web folders\ibm00001.dll -> Trojan.Agent.bu : Error during cleaning
[1964] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[1972] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[2016] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[288] C:\WINDOWS\newfrn.exe -> Spyware.Hijacker.Generic : Cleaned with backup
[296] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[316] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[416] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[348] C:\WINDOWS\omf.exe -> Spyware.Hijacker.Generic : Cleaned with backup
[540] C:\PROGRA~1\COMMON~1\qfow\qfowm.exe -> Downloader.TSUpdate.k : Cleaned with backup
[2312] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[3780] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[2384] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[2720] c:\program files\common files\microsoft shared\web folders\ibm00002.dll -> Logger.Small.dg : Error during cleaning
[2192] C:\WINDOWS\inet20003\mm4.exe -> Proxy.Delf.an : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\jiij.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\99_app99.exe -> Dropper.Agent.xw : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\adwsetup_upd.exe -> Dropper.Agent.abb : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\btnetw3.exe -> Not-A-Virus.Hoax.Win32.SpyWare.b : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@entrepreneur.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@findwhat[1].txt -> Spyware.Cookie.Findwhat : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Cookies\james@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\DB.tmp -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\DC.tmp -> Downloader.CWS.r : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\E7B17C.tmp/Quicklinks.exe -> Adware.MDH : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\GLF6GLF6.EXE -> Downloader.TSUpdate.f : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\i17F.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Temporary Internet Files\Content.IE5\GTUR0XQR\adsetup.silent.1.20[1].exe -> Dropper.Agent.abb : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Temporary Internet Files\Content.IE5\GTUR0XQR\newfrn[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Temporary Internet Files\Content.IE5\GTUR0XQR\omf[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\Temporary Internet Files\Content.IE5\GTUR0XQR\ts_8_new[1].exe -> Downloader.TSUpdate.f : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temp\ts_8_new.exe -> Downloader.TSUpdate.f : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\A8BQVN1R\kl[1].txt -> Trojan.Agent.bu : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\A8BQVN1R\ltndload[1].dll -> Adware.Sud : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\A8BQVN1R\paytime[1].txt -> Hijacker.StartPage.agt : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\A8BQVN1R\tool3[1].txt -> Downloader.Small.bwr : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\A8BQVN1R\tool5[1].txt -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\DW1AWNKK\ms1[1].txt -> Downloader.Tiny.al : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\DW1AWNKK\tool4[1].txt -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\DW1AWNKK\web[1].exe -> Downloader.CWS.r : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\E187YLY5\9400[1].cab/Quicklinks.exe -> Adware.MDH : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\GPKBGJWF\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\GPKBGJWF\AppWrap[2].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\GPKBGJWF\AppWrap[3].exe -> Spyware.Zestyfind : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\GPKBGJWF\installerus[1].exe -> Downloader.Qoologic.at : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\IVIFU9AV\101[1].wmf -> Not-A-Virus.Exploit.Win32.IMG-WMF : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\IVIFU9AV\inrh9400[1].exe -> Downloader.Small.bke : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K10L2BK1\drsmartloadb[1].exe -> Downloader.Adload.l : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\K10L2BK1\ppt1[1].exe -> Downloader.Small.cdy : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\NKB4DTO5\inst_0004[1].exe -> Downloader.Small.cam : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\NKB4DTO5\paradise[1].raw -> Proxy.Lager.f : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\NKB4DTO5\tool2[1].txt -> Not-A-Virus.Hoax.Win32.Renos.aj : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\NKB4DTO5\toolbar[1].txt -> Downloader.Adload.j : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\WRW6OA6W\country[1].htm -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\WRW6OA6W\drsmartload[1].exe -> Downloader.Adload.l : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\WRW6OA6W\file9[1].zip/crack.exe -> Downloader.PassAlert.h : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\WRW6OA6W\hosts[1].txt -> Trojan.Qhost.el : Cleaned with backup
C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\WRW6OA6W\tool1[1].txt -> Trojan.Small : Cleaned with backup
C:\inst_0004.exe -> Downloader.Small.cam : Cleaned with backup
C:\n.exe -> Downloader.Small.cdy : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe -> Trojan.Zapchast.ad : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\__delete_on_reboot__ibm00001.dll -> Trojan.Agent.bu : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\__delete_on_reboot__ibm00002.dll -> Logger.Small.dg : Cleaned with backup
C:\Program Files\Common Files\qfow\qfowa.exe -> Downloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\qfow\qfowd\qfowc.dll -> Downloader.Small : Cleaned with backup
C:\Program Files\Common Files\qfow\qfowl.exe -> Downloader.TSUpdate.j : Cleaned with backup
C:\Program Files\Common Files\qfow\qfowm.exe -> Downloader.TSUpdate.k : Cleaned with backup
C:\Program Files\Common Files\qfow\qfowp.exe -> Spyware.Xupiter : Cleaned with backup
C:\Program Files\Common Files\VCClient\SS1001.exe -> Dropper.Small.qn : Cleaned with backup
C:\Program Files\QL\uninstall.exe -> Adware.Suggestor : Cleaned with backup
C:\RECYCLER\S-1-5-21-1993962763-484061587-1801674531-1004\Dc13.exe -> Downloader.Adload.l : Cleaned with backup
C:\RECYCLER\S-1-5-21-1993962763-484061587-1801674531-1004\Dc14.exe -> Downloader.Small.bke : Cleaned with backup
C:\RECYCLER\S-1-5-21-1993962763-484061587-1801674531-1004\Dc15.exe -> Downloader.Adload.l : Cleaned with backup
C:\RECYCLER\S-1-5-21-1993962763-484061587-1801674531-1004\Dc4.zip/crack.exe -> Downloader.PassAlert.h : Cleaned with backup
C:\RECYCLER\S-1-5-21-1993962763-484061587-1801674531-1004\Dc5\crack.exe -> Downloader.PassAlert.h : Cleaned with backup
C:\WINDOWS\Aofvfcqj.dll -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\DH.dll -> Hijacker.Small.jf : Cleaned with backup
C:\WINDOWS\fdsobuwn.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\iconu.exe -> Spyware.Zestyfind : Cleaned with backup
C:\WINDOWS\inet20003\alg.exe -> Worm.Delf.i : Cleaned with backup
C:\WINDOWS\inet20003\alg.exe.bak -> Worm.Delf.i : Cleaned with backup
C:\WINDOWS\inet20003\mm4.exe -> Proxy.Delf.an : Cleaned with backup
C:\WINDOWS\inet20003\mm4.exe.bak -> Proxy.Delf.an : Cleaned with backup
C:\WINDOWS\kl.exe -> Trojan.Agent.bu : Cleaned with backup
C:\WINDOWS\msbk32.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\newfrn.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\omf.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\rpkroel.exe -> Dropper.Agent.mu : Cleaned with backup
C:\WINDOWS\system32\399.exe -> Dropper.Agent.xw : Cleaned with backup
C:\WINDOWS\system32\6367626563686E.exe -> Trojan.VB.aft : Cleaned with backup
C:\WINDOWS\system32\b2search.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\dccdvcv.exe -> Trojan.Pakes : Cleaned with backup
C:\WINDOWS\system32\dtti.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\dwdsregt.exe -> Spyware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\enpsl1771.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\idl.exe -> Downloader.Small.buy : Cleaned with backup
C:\WINDOWS\system32\kvvkg.dat -> Downloader.Qoologic.at : Cleaned with backup
C:\WINDOWS\system32\mc-110-12-0000121.exe -> Spyware.Maxifiles : Cleaned with backup
C:\WINDOWS\system32\nsq1B.dll -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\o2ro0c93ef.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\oqfox32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\paradise.raw -> Proxy.Lager.f : Cleaned with backup
C:\WINDOWS\system32\rndsregp.exe -> Spyware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\satl.exe -> Downloader.IstBar : Cleaned with backup
C:\WINDOWS\system32\ssmk.exe -> Dropper.Small.qn : Cleaned with backup
C:\WINDOWS\system32\wllwq.dll -> Downloader.Small : Cleaned with backup
C:\WINDOWS\system32\wuntrust.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\zdinst_CORN001.exe -> Spyware.ZenoSearch : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__04ug00pk.dll -> Adware.Sud : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__naansap.dll -> Downloader.Qoologic.az : Cleaned with backup
C:\WINDOWS\system32\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll -> Trojan.VB.aft : Cleaned with backup
C:\WINDOWS\Temp\bw2.com -> Spyware.Zestyfind : Cleaned with backup
C:\WINDOWS\tool2.exe -> Not-A-Virus.Hoax.Win32.Renos.aj : Cleaned with backup
C:\WINDOWS\tool3.exe -> Downloader.Small.bwr : Cleaned with backup
C:\WINDOWS\toolbar.exe -> Downloader.Adload.j : Cleaned with backup
::Report End
Edited by jameskris, 31 December 2005 - 03:49 PM.