i did what you said but it wont let me delete these
:\WINDOWS\system32\mswmmqce.dll
C:\WINDOWS\system32\rsmpmcis.dll
C:\WINDOWS\system32\shmecmse.dll
C:\WINDOWS\system32\ciaddavc.dll
:\WINDOWS\system32\mljgg.dll
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 07:59 06-08-07
+ Scan result:
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077838.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077839.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0024.CHK -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0076764.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0076788.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078864.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073774.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078870.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077836.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077837.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0079910.DLL -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079966.DLL -> Backdoor.Agent.adr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081130.exe -> Backdoor.Rbot.ben : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072734.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073734.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Paul\Local Settings\Application Data\Mozilla\Firefox\Profiles\ymfc27gv.default\Cache\71F545FEd01 -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0004.CHK -> Downloader.Agent.hy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077834.exe -> Downloader.Agent.hy : Cleaned with backup (quarantined).
C:\Program Files\Windows NT\nidyqyd.dll.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0029.CHK -> Downloader.Small.ctk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072754.exe -> Downloader.Small.ctk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073753.exe -> Downloader.Small.ctk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073789.exe -> Downloader.Small.ctk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078866.exe -> Downloader.Small.ctk : Cleaned with backup (quarantined).
C:\Documents and Settings\Paul\Desktop\New Folder\backups\backup-20060802-192659-482.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0076784.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0020.CHK -> Downloader.Small.cvs : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0016.CHK -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078868.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081132.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078859.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078857.exe -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078858.exe -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0017.CHK -> Downloader.Small.dic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072752.exe -> Downloader.Small.dic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073754.exe -> Downloader.Small.dic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073787.exe -> Downloader.Small.dic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077840.exe -> Downloader.Small.dic : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0023.CHK -> Downloader.Small.dkb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077842.exe -> Downloader.Small.dkb : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0007.CHK -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072748.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073749.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073784.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078869.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078860.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078863.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP231\A0080026.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined).
C:\t.inx -> Downloader.Tibs.gc : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0026.CHK -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072751.exe -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073750.exe -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077843.exe -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081134.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\WINDOWS\unin101.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0010.CHK -> Dropper.Agent.asr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0076776.exe -> Dropper.VB.kk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0076795.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078890.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Program Files\BHO Plugin\plugin.dll -> Hijacker.Small.ja : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072742.dll -> Hijacker.Small.ja : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073771.dll -> Hijacker.Small.ja : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077844.exe -> Logger.Mxsender.f : Cleaned with backup (quarantined).
C:\WINDOWS\system32\hksrv.dll -> Logger.Mxsender.f : Cleaned with backup (quarantined).
C:\WINDOWS\system32\prsvc.exe -> Logger.Mxsender.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Paul\Local Settings\Application Data\Mozilla\Firefox\Profiles\ymfc27gv.default\Cache\B23E4567d01 -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079916.DLL -> Proxy.Agent.df : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\snapshot\MFEX-1.DAT -> Proxy.Agent.df : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073772.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0074768.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077835.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077845.exe -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077852.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078854.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078855.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078865.EXE -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078892.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0079889.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0079897.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0079905.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079923.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079940.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079959.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079971.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP231\A0079984.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP231\A0079990.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP231\A0080008.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP231\A0080062.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0080077.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081071.DLL -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081077.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081121.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081129.dll -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP232\A0081133.exe -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\FOUND.013\FILE0008.CHK -> Proxy.Xorpix.ag : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072750.exe -> Proxy.Xorpix.ag : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073748.exe -> Proxy.Xorpix.ag : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073785.exe -> Proxy.Xorpix.ag : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078867.exe -> Proxy.Xorpix.ag : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0078872.exe -> Trojan.Dialer.pw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP230\A0079949.DLL -> Trojan.Opnis.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072749.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072753.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0072755.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073751.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073752.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073755.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073786.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0073788.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077841.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0077846.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7393D767-1F47-4FDC-85DC-79E4125CCEE2}\RP229\A0079909.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
::Report end
the panda one
Incident Status Location
Spyware:spyware/media-motor Not disinfected Windows Registry
Spyware:Cookie/Casalemedia Not disinfected C:\FOUND.001\FILE0001.CHK
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-224824.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-224825.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234839.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234840.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234841.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234842.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234843.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234844.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234845.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20060802-234846.backup
Adware:Adware/DigInk Not disinfected C:\WINDOWS\uni_ehhh.exe
Spyware:Cookie/YieldManager Not disinfected C:\FOUND.005\FILE0266.CHK
Spyware:Cookie/2o7 Not disinfected C:\FOUND.006\FILE0001.CHK
Virus:Trj/RootkitDrop.B Disinfected C:\FOUND.012\FILE0001.CHK
Adware:Adware/SystemDoctor Not disinfected C:\FOUND.013\FILE0000.CHK
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0011.CHK[²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0014.CHK
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0018.CHK[²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0018.CHK[²ÜÇ\nsProcess.dll]
Adware:Adware/NewAds Not disinfected C:\FOUND.013\FILE0018.CHK[¦&&\Windows\WinUpdate.exe]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0018.CHK[¦&&\Windows\WinUpdate.exe][²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0018.CHK[¦&&\Windows\WinUpdate.exe][²ÜÇ\nsProcess.dll]
Adware:Adware/NewAds Not disinfected C:\FOUND.013\FILE0018.CHK[¦&&\Windows\WinUpdate.exe][²ªÇ]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0019.CHK[²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0019.CHK[²ÜÇ\nsProcess.dll]
Adware:Adware/NewAds Not disinfected C:\FOUND.013\FILE0019.CHK[¦&&\Windows\WinUpdate.exe]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0019.CHK[¦&&\Windows\WinUpdate.exe][²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0019.CHK[¦&&\Windows\WinUpdate.exe][²ÜÇ\nsProcess.dll]
Adware:Adware/NewAds Not disinfected C:\FOUND.013\FILE0019.CHK[¦&&\Windows\WinUpdate.exe][²ªÇ]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0027.CHK
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0032.CHK[²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\FOUND.013\FILE0032.CHK[²ÜÇ\nsProcess.dll]
Adware:Adware/NewAds Not disinfected C:\FOUND.013\FILE0032.CHK[²ªÇ]
Spyware:Cookie/WUpd Not disinfected C:\FOUND.015\FILE0000.CHK
Spyware:Cookie/DriveCleaner Not disinfected C:\FOUND.015\FILE0004.CHK
Spyware:Cookie/DriveCleaner Not disinfected C:\FOUND.015\FILE0009.CHK
Spyware:Cookie/Searchportal Not disinfected C:\FOUND.015\FILE0019.CHK
Logfile of HijackThis v1.99.1
Scan saved at 11:20, on 06-08-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mswmmqce.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Paul\Desktop\New Folder\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [clcbt.exe] C:\WINDOWS\system32\clcbt.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [1c9533f4.exe] C:\Documents and Settings\Paul\Local Settings\Application Data\1c9533f4.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{918C79A8-7413-4598-9CA1-C2FB83BBE473}: NameServer = 205.188.146.145
O20 - AppInit_DLLs: shmecmse.dll ciaddavc.dll
O21 - SSODL: DCOM Server 2240 - {2C1CD3D7-86AC-4068-93BC-A02304BB2240} - C:\WINDOWS\system32\2240_28.dll (file missing)
O21 - SSODL: FvCbll - {0F1A1BF6-A5B0-B15C-1FC6-DBCC512310CD} - C:\WINDOWS\system32\elis.dll (file missing)
O21 - SSODL: hksrv.dll - {9B4B67AA-F230-4602-8344-66104AFB4A25} - hksrv.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
thanks the excellent advice and help