Virus is still there.
Thanks for ur help.
I have done excatly as above.
Well...i also get a message from Norton antivirus saying that it has detected the Backdoor.DSNX virus in C:/WINDOWS?TEMPu17.bat
DOMAIN NAME: WORKGROUP
Also these are the startup at the moment.
---------------------------------------------------------
ewido security suite - Startup report
---------------------------------------------------------
+ Created on: 8:57:11 AM, 8/26/2005
+ Report-Checksum: E98CBE01
Reg\HKLM\Run vidctrl C:\WINDOWS\system32\vidctrl\vidctrl.exe
Reg\HKLM\Run winsync C:\WINDOWS\system32\l4slkd.exe reg_run
Reg\HKLM\Run SurfSideKick 3 C:\Program Files\SurfSideKick 3\Ssk.exe
Reg\HKLM\Run 3un41bsg C:\WINDOWS\system32\3un41bsg.exe
Reg\HKLM\Run stb C:\WINDOWS\system32\stb.exe
Reg\HKLM\Run ZStart c:\windows\system32\qpdxregv.exe DO0605
Reg\HKLM\Run SysStart C:\WINDOWS\system32\ssysrx2d.exe DO0605
Reg\HKCU\Run RecordNow!
Reg\HKCU\Run SurfSideKick 3 C:\Program Files\SurfSideKick 3\Ssk.exe
Shell\CommonStartup nprn.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nprn.exe
Shell\CommonStartup Service Manager.lnk C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
Shell\UserStartup Zeno.lnk C:\Documents and Settings\sandeep\Start Menu\Programs\Startup\Zeno.lnk
Shell\UserStartup Zstart.lnk C:\Documents and Settings\sandeep\Start Menu\Programs\Startup\Zstart.lnk
Here is the fresh log from:
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at
http://www.greyknight17.com/download.htm#programs
***Security Programs Detected***
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Logfile of HijackThis v1.99.1
Scan saved at 9:02:38 AM, on 8/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\system32\3un41bsg.exe
C:\WINDOWS\system32\vidctrl\vidctrl.exe
c:\windows\system32\qpdxregv.exe
C:\WINDOWS\system32\ssysrx2d.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.ieplugin.com/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O2 - BHO: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
O2 - BHO: LinkTracker Class - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - C:\WINDOWS\system32\qlink32.dll
O3 - Toolbar: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\l4slkd.exe reg_run
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [3un41bsg] C:\WINDOWS\system32\3un41bsg.exe
O4 - HKLM\..\Run: [stb] C:\WINDOWS\system32\stb.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\system32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [ZStart] c:\windows\system32\qpdxregv.exe DO0605
O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\system32\ssysrx2d.exe DO0605
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\ssysrx2d.exe
O4 - Startup: Zstart.lnk = C:\Documents and Settings\sandeep\Local Settings\Temp\zxinst12.exe
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Microsoft AntiSpyware helper - {8FF5F54D-0589-455C-9F40-464A27BEA739} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8FF5F54D-0589-455C-9F40-464A27BEA739} - (no file) (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) -
http://www.loksatta.com/daily/dynamic/wfplayer/tdserver.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} -
http://downloads.shopathomeselect.com/cpi/grinstall_cpi1001.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123516343921
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) -
http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINDOWS\system32\qlink32.dll
O20 - AppInit_DLLs: repairs.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\mbang.dll
O23 - Service: ASP.NET Admin Service (aspnet_admin) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: COM+ Runtime Service (CORRTSvc) - Unknown owner - %WinDIR%\System32\svchost.exe (file missing)
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
End of KRC HijackThis Analyzer Log.
==========================================================
Here is Ewido Results
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 7:10:48 PM, 8/25/2005
+ Report-Checksum: 7D2F3BF0
+ Scan result:
HKLM\SOFTWARE\Bargains -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\CashBack -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{83DC91DB-7896-43E3-B34D-A7D043F16BB1} -> Spyware.ClearStream : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{99410CDE-6F16-42ce-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CE7EF827-47CC-48EB-B570-C367F1E1277E} -> Spyware.RideMG : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DAB941D8-BC94-4819-AB4D-5598C65FA3FE} -> Spyware.Begin2Search : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1CFB8B32-4053-4144-AF6F-1540EEC7F101} -> Spyware.Adlogix : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{09CA52B3-703C-4B17-9690-C13F736E3DCD} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073} -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5B6689B5-C2D4-4DC7-BFD1-24AC17E5FCDA} -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\eXactUtil -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{99410CDE-6F16-42ce-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BargainBuddy -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CashBack -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eXactAdvertisingFuncade -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NaviSearch -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Surf SideKick -> Spyware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\NaviSearch -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\SecureWin -> Spyware.Adlogix : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\dsktb -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\dsktb\DesktopToolbar -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config\button0 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config\button1 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config\button2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config\button3 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\Config\KeyWordFreqCap -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-DD60-0064-6EC2-6E0100000000} -> Spyware.MediaMotor : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000049-8F91-4D9C-9573-F016E7626484} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{16B238D5-80DE-47CE-8F17-B3ECE2C2248D} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Spyware.IEPageHelper : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{207AEF46-0596-4966-A7BF-098F247E85BB} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{52FE5233-367C-4EFB-BDD7-0BE4D212C107} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83DC91DB-7896-43E3-B34D-A7D043F16BB1} -> Spyware.ClearStream : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{988CAFC4-DC0D-4D8C-A35E-5028ABE9E641} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99410CDE-6F16-42CE-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CE7EF827-47CC-48EB-B570-C367F1E1277E} -> Spyware.RideMG : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-DD60-0064-6EC2-6E0100000000} -> Spyware.MediaMotor : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000049-8F91-4D9C-9573-F016E7626484} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{16B238D5-80DE-47CE-8F17-B3ECE2C2248D} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Spyware.IEPageHelper : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{207AEF46-0596-4966-A7BF-098F247E85BB} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{52FE5233-367C-4EFB-BDD7-0BE4D212C107} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83DC91DB-7896-43E3-B34D-A7D043F16BB1} -> Spyware.ClearStream : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{988CAFC4-DC0D-4D8C-A35E-5028ABE9E641} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE7EF827-47CC-48EB-B570-C367F1E1277E} -> Spyware.RideMG : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\WinUpdt -> Spyware.SecondThought : Cleaned with backup
HKU\S-1-5-21-2506135919-917291314-3849292660-1006\Software\{12EE7A5E-0674-42f9-A76B-000000004D00} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
[236] C:\WINDOWS\system32\mbang.dll -> Spyware.Look2Me : Error during cleaning
[692] C:\WINDOWS\system32\mxc70u.dll -> Spyware.Look2Me : Error during cleaning
[780] C:\WINDOWS\system32\joejd.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\sandeep\Cookies\sandeep@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temp\DelC.tmp -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temp\ICD1.tmp\wupdt.exe -> Spyware.Imiserverieplugin : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temp\resD.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\BFLJR1CW\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\BFLJR1CW\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\BFLJR1CW\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\BFLJR1CW\AppWrap[4].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\ET30DKNE\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\ET30DKNE\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\G7FRIGH1\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\G7FRIGH1\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\G7FRIGH1\upd209[1].exe -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\GXY3W9EZ\upd208[1].exe -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\H4OFPDW9\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\H4OFPDW9\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\H4OFPDW9\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\K8QWL4P0\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\K8QWL4P0\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\M4H8XOTT\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\M4H8XOTT\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\M4H8XOTT\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\QIBH8APJ\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\QIBH8APJ\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\QIBH8APJ\website[1].ocx -> TrojanDownloader.Agent.ex : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\WAWLSJUT\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\WAWLSJUT\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\WAWLSJUT\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\XN9K7NKJ\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\XN9K7NKJ\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\XN9K7NKJ\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\YR2AHESG\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\YR2AHESG\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\YR2AHESG\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\sandeep\Local Settings\Temporary Internet Files\Content.IE5\Z9947HNZ\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Program Files\180searchassistant\sac.exe -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\180searchassistant\sachook.dll -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\BullsEye Network\bin\adv.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\BullsEye Network\bin\adx.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\BullsEye Network\bin\bargains.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\CashBack -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\ad.dat -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bb_auto_wider.swf -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bb_click_wider.swf -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bb_welcome.html -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bb_welcome1.swf -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bin -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bin\cashback.exe -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bin\cb.exe -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\bin\flash.exe -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\blank.gif -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\icon.gif -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\logo.gif -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\template.html -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\template2.html -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\ub.dat -> Spyware.CashBack : Cleaned with backup
C:\Program Files\CashBack\Uninstall.exe -> Spyware.CashBack : Cleaned with backup
C:\Program Files\Common Files\Java\flacpy.cfg -> Spyware.FlashEnhancer : Cleaned with backup
C:\Program Files\Common Files\system32.dll/Catcher.dll -> Spyware.Maxifiles : Error during cleaning
C:\Program Files\Common Files\system32.dll/gui.exe -> TrojanDownloader.Agent.rv : Error during cleaning
C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe -> Spyware.Delfin : Cleaned with backup
C:\Program Files\DNS\Catcher.dll -> Spyware.Maxifiles : Cleaned with backup
C:\Program Files\DNS\gui.exe -> TrojanDownloader.Agent.rv : Cleaned with backup
C:\Program Files\NaviSearch\bin\nls.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\abi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\installer_MARKETING11.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\installer_VENDARE.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\website.ocx -> TrojanDownloader.Agent.ex : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\installer_MARKETING11.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\installer_VENDARE.exe -> TrojanDownloader.Adload.a : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\website.ocx -> TrojanDownloader.Agent.ex : Cleaned with backup
C:\WINDOWS\extract.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\iexplore.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\invitessk.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\isrvs\isearch.xpi/chrome/isearch.jar/content/isearch/isearch.js -> Spyware.iSearch : Cleaned with backup
C:\WINDOWS\ivsbyd.exe -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\ljbhdymd.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\optimize.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar : Cleaned with backup
C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\88ac09g5.exe -> Adware.Saha : Cleaned with backup
C:\WINDOWS\system32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\ca2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\Cache\Installer.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ceidnd.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\ceidnf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\cxdxregt.exe -> Trojan.Zx.12 : Cleaned with backup
C:\WINDOWS\system32\dovxdec_0411.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\drivers\df_kmd.sys -> Trojan.Rootkit.Agent.af : Cleaned with backup
C:\WINDOWS\system32\dsktrf.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\dsktrf1.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\Ednqhm.exe -> TrojanDownloader.Agent.hw : Cleaned with backup
C:\WINDOWS\system32\exul.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exul1.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exul3.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\iv41_qcx.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\javexulm.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\jkzspz.exe -> Trojan.Agent.ay : Cleaned with backup
C:\WINDOWS\system32\knrr5ki7.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\lanbrup.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\lppcx11n.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\msbe.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\mscb.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\nsbC.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\nsh16.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\nss11.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\nsvsvc\nsv.ocx -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\system32\nsvsvc\nsvs.dll -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe -> Spyware.Delfin : Cleaned with backup
C:\WINDOWS\system32\nvms.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\p88fk7jj.dll -> Adware.Saha : Cleaned with backup
C:\WINDOWS\system32\pbwpq.dat -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\WINDOWS\system32\qeiwawqk.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\qmfpud.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\qmfpuf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\qpdxregv.exe -> Trojan.Zx.12 : Cleaned with backup
C:\WINDOWS\system32\redtrsha.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\richedtr.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\richup.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\rtneg4.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\shlnt97.exe -> TrojanDownloader.Apropo.ac : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\wexrag.exe -> TrojanDownloader.Apropo.ac : Cleaned with backup
C:\WINDOWS\system32\xiyfhc.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\xiyfhd.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\system32\xiyfhf.exe -> Spyware.Adstart : Cleaned with backup
C:\WINDOWS\tct101.dll -> TrojanDownloader.Dyfuca.eg : Cleaned with backup
C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Error during cleaning
C:\WINDOWS\Temp\Cookies\sandeep@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@as-eu.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@findwhat[1].txt -> Spyware.Cookie.Findwhat : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@pro-market[1].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\sandeep@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\WINDOWS\Temp\SSK3_B5.exe -> TrojanDropper.Small.qn : Cleaned with backup
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8NOFA9QT\pcs_0026[1].exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\Temp\w181609.Stub.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
C:\WINDOWS\Temp\zxinst12.exe -> Trojan.Zx.12 : Cleaned with backup
C:\WINDOWS\wdskctl.exe -> Spyware.ShopNav : Cleaned with backup
C:\WINDOWS\wupdt.exe -> Spyware.Imiserverieplugin : Cleaned with backup
::Report End
------------------------------------