View Single Post
Old 01-05-2006, 09:53 AM   #11 (permalink)
K'nolla
Registered User
 
Join Date: Jun 2005
Posts: 50
OS: XP


.................Here's The HJL.......................

Logfile of HijackThis v1.99.1
Scan saved at 16:51:30, on 05/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Documents and Settings\Kofo\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CPQHotkeys] hotkeysvc.exe
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [workflow] D:\installs\workflow.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\RunServices: [CPQHotkeys] hotkeysvc.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [CPQHotkeys] hotkeysvc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /Minimized
O4 - HKCU\..\RunServices: [CPQHotkeys] hotkeysvc.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/...gameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


..................Here's The Online Scan...........................

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, January 05, 2005 16:51:03
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 5/01/2006
Kaspersky Anti-Virus database records: 169277
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 89471
Number of viruses found: 13
Number of infected objects: 142
Number of suspicious objects: 2
Duration of the scan process: 3611 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01F62821 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04432C2F Infected: Trojan-Downloader.Win32.Wintool.a
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\05DE4871 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\094E51FD.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09B44805.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\14DE0DFC.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\15440403.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E937F55 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F951475.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F983E71.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F9C686E.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F9F126A.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA23C66.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA66663.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA9105F.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FAC3A5C.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FAF6458.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FB30E54.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FB63851.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FB9624D.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FBC0C4A.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC03646.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC36042.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC60A3F.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC9343B.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FCD5E38.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FD00834.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FD6172A.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20466FB3.fr1 Infected: Trojan.Win32.Crypt.t
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20D54002.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\218011E4.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\22A23FC6 Infected: Trojan-Downloader.Win32.Wintool.a
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23833DD4 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23FA4399 Infected: Trojan-Downloader.Win32.Wintool.a
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26F76926.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2C657C00.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E173B22.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\331B5CD5 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\370E5AA1.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37142E99.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37F637FF.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\385C2E07.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A9C5ED4 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\403B26D4 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\416B363E Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\438673FE.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43EC6A05.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\49E7713C Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4AAC5808 Infected: Trojan-Downloader.Win32.Wintool.a
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F162FFC.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\52356203.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57B30CB4.frC Infected: Trojan-Downloader.Win32.IstBar.gen
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57B960AD.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AA76BFB.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B0D6202.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60E43EA8 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\622B11E0.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65496EE4.exe Infected: Backdoor.Win32.Prorat.ae
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\669D1E01.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67BD0898 Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BA84A0E Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C2B4179.tmp Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71EA6F3A Infected: not-a-virus:AdWare.Win32.Wintol.p
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\722D5A00.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72F702B4 Infected: Trojan-Downloader.Win32.Wintool.a
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DBE15FE.tmp Infected: Email-Worm.Win32.VB.an
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7E240C06.tmp Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0025999.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026000.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026001.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026002.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026003.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026004.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026005.sys Suspicious: Rootkit.Win32.Agent.ao
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP114\A0026008.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028119.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028120.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028121.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028122.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028123.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028124.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028125.sys Suspicious: Rootkit.Win32.Agent.ao
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP122\A0028130.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP129\A0029279.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032012.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033126.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033127.ocx Infected: not-a-virus:Porn-Dialer.Win32.Creazione.x
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033128.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033129.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033130.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033131.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033132.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033133.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033134.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033135.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033136.exe Infected: not-virus:Hoax.Win32.Renos.a
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033137.exe Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033138.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033139.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035731.dll Infected: not-a-virus:Dialer.Win32.BT.c
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035732.dll Infected: not-a-virus:AdWare.Win32.MyWebSearch
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035733.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035734.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035735.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035736.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035737.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035738.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035739.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035740.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035741.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035742.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035743.exe Infected: Trojan-Downloader.Win32.Small.bhp
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035744.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035745.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035746.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035747.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035748.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035749.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035750.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035751.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035752.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035753.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035754.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035755.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035756.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035757.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035758.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035759.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035760.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035761.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035762.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035763.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035764.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035765.exe Infected: Backdoor.Win32.Prorat.ae
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035766.scr Infected: not-a-virus:AdWare.Win32.MyWebSearch
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP147\A0035767.exe Infected: Trojan-Downloader.Win32.Small.bhp
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023461.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023462.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023465.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023466.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023467.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023468.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP89\A0023473.dll Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\SYSTEM32\irctplug.exe Infected: Trojan.Win32.Crypt.t

Scan process completed.


........................Here's The Ewido..................................

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 13:01:26, 05/01/2005
+ Report-Checksum: 7D0514C5

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-2626194381-1693727974-1655961439-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-2626194381-1693727974-1655961439-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-2626194381-1693727974-1655961439-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-2626194381-1693727974-1655961439-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
C:\Program Files\Internet Explorer\BTOW Shared Files\btwebcontrol.dll -> Dialer.Generic : Cleaned with backup
C:\Program Files\MSN Messenger\riched20.dll -> Spyware.MyWebSearch : Cleaned with backup
C:\RECYCLER\NPROTECT\00271388.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271389.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271401.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271408.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271449.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271450.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271467.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271922.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271923.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00271947.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00272074.exe -> Downloader.Small.bhp : Cleaned with backup
C:\RECYCLER\NPROTECT\00273357.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273361.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273382.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273393.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273446.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273447.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273459.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273466.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273481.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273482.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00273494.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274448.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274452.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274471.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274480.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274714.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274718.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274739.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00274747.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00275229.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00275230.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\RECYCLER\NPROTECT\00275248.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP139\A0030510.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP139\A0030511.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031975.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031976.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031977.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031979.exe -> Worm.VB.an : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031980.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031981.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031982.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031983.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031984.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031985.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031986.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031987.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031988.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031989.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031990.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031991.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031992.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031993.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031994.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031995.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031996.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031997.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031998.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0031999.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032000.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032001.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032002.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032003.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032004.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032005.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032006.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032007.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032008.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032009.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032010.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP145\A0032011.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033193.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033194.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033195.exe -> Backdoor.Prorat.s : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP146\A0033200.exe -> Worm.VB.an : Cleaned with backup
C:\WINDOWS\SYSTEM32\f3PSSavr.scr -> Spyware.MyWebSearch : Cleaned with backup
C:\WINDOWS\SYSTEM32\lncom.exe -> Downloader.Small.bhp : Cleaned with backup


::Report End


My PC is still slow at start up, and also it says that i have new installed programmes when i dont. It highlights current programmes as newley installed in the start menu.
K'nolla is offline