Desktop Hijack Update
Thanks for your help sUBs. I followed your instructions to the letter and I can now have control of the desktop background again. However, one thing that didn't work is smitRem. I ran the app but when it was scanning through the files they were all saying "error file not found". The end result was it didn't create any log file. Did I miss something simple or is there another problem?
Anyway Here's the HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 11:49:55 PM, on 24/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\zHotkey.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & De
stroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
Here's the Ewido scan report:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:08:44 PM, 24/10/2005
+ Report-Checksum: 5B6CEDFA
+ Scan result:
C:\HiJackThis\backups\backup-20051024-202237-964.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWAS5LP_0001_0811NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\WINDOWS\q1188781.dll -> TrojanDownloader.Delf.wp : Cleaned with backup
C:\WINDOWS\system32\Axtucn.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\ca2.dll -> Spyware.SearchIt : Cleaned with backup
C:\WINDOWS\system32\drivers\df_kmd.sys -> Trojan.Rootkit.Agent.af : Cleaned with backup
C:\WINDOWS\system32\dun.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\tmp.exe -> TrojanDownloader.Delf.uj : Cleaned with backup
:mozilla.8:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.19:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.20:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.23:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.24:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.26:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.27:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.28:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.29:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.30:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.31:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.32:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.35:E:\Documents and Settings\Guest\Application Data\Phoenix\Profiles\default\7j9vuq7g.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
E:\Documents and Settings\Guest\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
E:\Documents and Settings\Guest\Cookies\
[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
E:\Documents and Settings\Guest\Cookies\
[email protected][2].txt -> Spyware.Cookie.Lop : Cleaned with backup
:mozilla.6:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.35:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.36:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.37:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.38:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.102:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.103:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.108:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.109:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.120:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.121:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.122:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.123:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.124:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.125:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.134:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.135:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.136:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.137:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.151:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.163:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.164:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.183:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\default\5lat6g81.slt\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.6:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.7:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.8:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.11:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.12:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.13:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.15:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.19:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.20:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.21:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.22:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.23:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.24:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.25:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.31:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.47:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.60:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.92:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.93:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.97:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.115:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.116:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.117:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.118:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.119:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.130:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.131:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.133:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.134:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.135:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.163:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.169:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.170:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.171:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.179:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.180:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.181:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.182:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.183:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.184:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.185:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.186:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.187:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.188:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.189:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.190:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.191:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.192:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.193:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.195:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.196:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.197:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.198:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.202:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.209:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.210:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.211:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.212:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.214:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.215:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.216:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.228:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.229:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.230:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.250:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.262:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.266:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.267:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.268:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.285:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.286:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.289:E:\Documents and Settings\Jude\Application Data\Phoenix\Profiles\peter1\7ho4pnol.slt\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.66.220.17.154 : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\Cookies\
[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
E:\Documents and Settings\Jude\My Documents\My Received Files\Messenger Plus! - Setup.exe/Sponsor.exe -> TrojanDownloader.Swizzor.bt : Cleaned with backup
:mozilla.8:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.19:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.20:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.30:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.32:E:\Documents and Settings\Jude5\Application Data\Phoenix\Profiles\default\klt165lu.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
E:\Documents and Settings\Jude5\Cookies\
[email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
E:\Documents and Settings\Jude5\Local Settings\Temporary Internet Files\Content.IE5\CR0JGVEN\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup
E:\Documents and Settings\Peter\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
E:\Documents and Settings\Peter\Cookies\
[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
E:\Documents and Settings\Peter\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
E:\Documents and Settings\Peter\Cookies\
[email protected][1].txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
E:\WINDOWS\system32\bcoret.exe/explorer.sys -> Worm.Tzet : Cleaned with backup
E:\WINDOWS\Temp\ClrSch\FNuninstaller.EXE -> Spyware.ClearSearch : Cleaned with backup
::Report End
Here's the Panda Activescan report:
Incident Status Location
Adware:Adware/Searchterror No disinfected C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Desktop.htt
Adware:adware/cws No disinfected C:\Documents and Settings\Admin\Favorites\Forbidden Conversations.url
Possible Virus. No disinfected C:\Games\Legends\Legends.exe
Virus:Trj/Topor.A Disinfected C:\prog.pif
Adware:Adware/eZula No disinfected C:\WINDOWS\system32\ezPopStub.exe
Adware:adware/craft No disinfected C:\WINDOWS\system32\mscnf.dll
Spyware:Spyware/LinkReplacer No disinfected C:\WINDOWS\system32\PreUninstallQL.exe
Virus:W32/Parite.B Disinfected E:\Documents and Settings\Administrator.FENWICK0\Local Settings\Temp\Deltmp.RB0
Adware:Adware/Lop No disinfected E:\Documents and Settings\All Users\Application Data\soft poke platform pop\ante surf.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\All Users\Application Data\soft poke platform pop\Knobbend.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\All Users\Application Data\soft poke platform pop\Style free.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\All Users\Application Data\soft poke platform pop\Trans Close.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\All Users\Application Data\soft poke platform pop\Wavebags.exe
Virus:W32/Parite.B Disinfected E:\Documents and Settings\All Users\Documents\DivXPro505GAINBundle.RB0
Virus:W32/Parite.B Disinfected E:\Documents and Settings\All Users\Documents\klcodec204f.RB0
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\ecrfsdas.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\jugs manager aim mfcd.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\kowtjrvw.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\mags stop chin.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\nlpubcwn.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\roxjbgzn.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\SetupTrayDefy.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Application Data\Beep wave help\zmcphxgc.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\85db6305.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\8fb1457a.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\9ab89ae9.exe
Adware:Adware/IPInsight No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\alchem.inf
Adware:Adware/IPInsight No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\alchem.ini
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\bawvdnwz.exe
Spyware:Spyware/BetterInet No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\II247.tmp
Spyware:Spyware/BetterInet No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\II248.tmp
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\Inside Program.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\jbijxqhu.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\jryvpfbk.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\lhppnzdf.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\ppqmqpgf.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\qfsvyqgb.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\sta4ED.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\sta525.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\staC3.exe
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\staC5.exe
Adware:Adware/Twain-Tech No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\twaintec.inf
Adware:Adware/Lop No disinfected E:\Documents and Settings\Jude\Local Settings\Temp\wjmfvarj.exe
Virus:W32/Parite.B Disinfected E:\Documents and Settings\Jude\My Documents\My Received Files\bittorrent-3.2.1.RB0
Virus:W32/Parite.B Disinfected E:\Documents and Settings\Peter\Local Settings\Temp\p2psetup.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\30.82_winxp.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\AcroReader51_ENU_full.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\BIEsetup.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\daemon333.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\DAMN_NFO_Viewer_v2.10.0031.RC3_Setup.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\DivXPro505GAINBundle.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\dk25inst.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\FileZilla_2_2_4f_setup.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\HijackThis.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\kazza.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\klcodec224f.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\kmd.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\SLPhotoBasic.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\spellcraft-full-v1.3f\Spellcraft.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\ts2_client_rc2_2029.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\ventrilo-2.2.0-Windows-i386.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\wace25.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\winamp291_full.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\winamp502_snowpatrol.RB0
Virus:W32/Parite.B Disinfected E:\Downloads\wrar320.RB0
Virus:W32/Parite.B Disinfected E:\MIRC\DOWNLOAD\DefilerPak-1.09.RB0
Virus:W32/Parite.B Disinfected E:\MIRC\DOWNLOAD\Tribes\lizExtra\lizExtraDatetime_date.RB0
Virus:W32/Parite.B Disinfected E:\MIRC\DOWNLOAD\Tribes\lizExtra\lizExtraDatetime_sleep.RB0
Virus:W32/Parite.B Disinfected E:\MIRC\mirc32.RB0
Virus:W32/Parite.B Disinfected E:\MIRC\mlink32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Batch Image Editor\BatchImageEditor.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\BitTorrent\btdownloadgui.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Adobe\ESD\AdobeDownloadManager.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Adobe\ESD\uninst.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\IDriver.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\knlwrap.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Microsoft Shared\Artgalry\ARTGALRY.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Microsoft Shared\Artgalry\CAG.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Microsoft Shared\MSInfo\OFFPROV.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Common Files\Real\Update\rnuninst.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\AUDIO\CTSetup\ctsetup.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\Installation\FireNet\FireNIns.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\Product Registration\English\InetReg.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\AudioHQ\Ahqrun.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\AudioHQ\AHQTbU.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\AudioHQ\AudioHQU.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Demo\CTSBAXP.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Demo\data\demoplay.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Demo\data\eacontrol.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Demo\data\eaplayer.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Demo\data\ldemo.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Diagnostics\CTCplFW.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\MiniDisc\CTMDCen.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\PlayCenter2\CTDBMig.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\PlayCenter2\CTP2Wiz.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\PlayCenter2\CTPlay2.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\PlayCenter2\MDBUtil.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Program\ADGJDet.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Program\CTEaxSpl.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Program\CTZAPXX.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Program\demo32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\QuickStart\demo32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\QuickStart\QuickStart.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Sound Blaster Audigy Manual\English\CTPdfErr.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Sound Blaster Audigy Manual\English\CTPdflnk.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\SurMix2\SurMix2.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Taskbar\CTLTask.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\SBAudigy\WaveStudio\CTWave32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\ShareDLL\CTNotify.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\ShareDLL\Mediadet.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\Uninstall\CTUninst.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Creative\Uninstall\_ISDel.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\D-Tools\daemon.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Dacris Benchmarks 5.0\BMark.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\DAMN NFO Viewer\DAMN NFO Viewer.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\DAMN NFO Viewer\UnInstall.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\DivX\DivX Pro Codec\config.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\DivX\DivX Pro Codec\DivX EKG.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\FileZilla\filezilla.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\FileZilla\FzSFtp.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\FileZilla\uninstall.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\GameSpy Arcade\ArcadePatch13c_13d.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\GameSpy Arcade\ArcadePatch13d_13e.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\GameSpy Arcade\ArcadePatch13e_13f.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\GlobalSCAPE\CuteFTP\newstub.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\AOD\aod_install.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\ICQLite.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\ICQLiteDBConverter.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\ICQLiteUninstall.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\ICQLRun.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\ICQLSRP.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\ICQLite\Unwise32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\InstallShield Installation Information\{18DF995F-2ACC-47E4-A33B-A703F4D39E92}\IS6.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Internet Explorer\IE Uninstall\w2kexcp.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Internet Explorer\ie6setup.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Internet Explorer\W2K\expinst.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\javaw.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\jpicpl32.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\keytool.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\kinit.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\klist.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\ktab.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\orbd.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\policytool.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\rmid.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\rmiregistry.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\servertool.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\bin\tnameserv.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java\j2re1.4.1_02\javaws-1_2_0_02-windows-i586-i.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java Web Start\helper.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java Web Start\javaws.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Java Web Start\uninst-javaws.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\K-Lite Codec Pack\3ivxConfig.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\K-Lite Codec Pack\fourcc.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\K-Lite Codec Pack\gspot.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\K-Lite Codec Pack\LSMpgCfg.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\K-Lite Codec Pack\unins000.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Messenger\msmsgs.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Messenger\msmsgsin.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Microsoft Office\Office\GRAPH9.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Microsoft Office\Office\MSOHTMED.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Microsoft Office\Office\OSA9.RB0
Virus:W32/Parite.B Disinfected E:\Program Files\Microsoft Office\Office\POWERPNT.RB0
Adware:Adware/SAHAgent No disinfected E:\WINDOWS\system32\xmltok.dll
Spyware:Spyware/ClearSearch No disinfected E:\WINDOWS\Temp\ClrSch\FNuninstaller.EX_[FNuninstaller.EXe]
End Report.
I think that's everything, hopefully I did what you told me correctly. Any feedback would be appreciated. Thanks very much.
Peter.