Thank you very much, here is new htl:
Logfile of HijackThis v1.99.1
Scan saved at 10:18:56 PM, on 5/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)
Running processes:
C:\WINDXP\System32\smss.exe
C:\WINDXP\system32\winlogon.exe
C:\WINDXP\system32\services.exe
C:\WINDXP\system32\lsass.exe
C:\WINDXP\system32\svchost.exe
C:\WINDXP\System32\svchost.exe
C:\WINDXP\system32\LEXBCES.EXE
C:\WINDXP\system32\spoolsv.exe
C:\WINDXP\system32\LEXPPS.EXE
C:\WINDXP\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDXP\System32\svchost.exe
C:\WINDXP\Explorer.EXE
C:\WINDXP\system32\wscntfy.exe
C:\WINDXP\system32\MsgSys.EXE
C:\Program Files\Iomega HotBurn\Autolaunch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe
C:\WINDXP\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDXP\system32\ctfmon.exe
C:\WINDXP\system32\j?vaw.exe
C:\PROGRA~1\COMMON~1\SSEMBL~1\winspool.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDXP\system32\wuauclt.exe
C:\WINDXP\system32\HPZinw12.exe
C:\WINDXP\system32\cidaemon.exe
C:\WINDXP\system32\cidaemon.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\WINDXP\System32\WISPTIS.EXE
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Stevo\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - URLSearchHook: (no name) - {1F1C6D28-A4E2-D831-C00F-DB98BC15F793} - (no file)
R3 - URLSearchHook: (no name) - {184F6E79-A9BE-8936-C00F-DB98BC15F7CB} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDXP\system32\ctfmon.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [okqi] C:\Program Files\Common Files\okqi\okqim.exe
O4 - HKCU\..\Run: [opmrket] C:\WINDXP\opmrket.exe
O4 - HKCU\..\Run: [Nbyrtf] C:\WINDXP\system32\j?vaw.exe
O4 - HKCU\..\Run: [irssyncd] C:\WINDXP\system32\irssyncd.exe
O4 - HKCU\..\Run: [Ucto] "C:\PROGRA~1\COMMON~1\SSEMBL~1\winspool.exe" -vt tzt
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Startup: Z_Start.lnk = C:\WINDXP\system32\dwdsregt.exe
O4 - Startup: Zeno.lnk = C:\WINDXP\system32\rwinksap.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with Go!Zilla -
file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .asp: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O13 - WWW. Prefix: http://
O15 - Trusted Zone:
http://www.pandasoftware.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v ... 5555702763
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
https://webchat.dell.com/Media/VisitorC ... EFlash.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan ... asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{374FCD0E-36DC-4F4A-8A78-602B778DF8CB}: NameServer = 10.0.10.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1D6BE43-46A0-4B97-8B62-D080E998EFB0}: NameServer = 10.0.10.1
O20 - Winlogon Notify: NavLogon - C:\WINDXP\System32\NavLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDXP\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDXP\System32\HPZipm12.exe
EWIDO log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 2:50:50 PM, 5/26/2006
+ Report-Checksum: 4045F0B7
+ Scan result:
HKLM\SOFTWARE\Classes\Interface\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01EB5130-FC0C-4D75-B9CE-4801B1B854F5} -> Adware.Begin2Search : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2296428D-C133-4928-B76A-A200FF409572} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{279A1B41-6CAC-4ABF-B39C-72C8E489F685} -> Adware.AdBlaster : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6001CDF7-6F45-471B-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95C60327-8E17-44D6-98EB-7EB70CC606DD} -> Adware.SafeSurfing : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5AF2622-8C75-4DFB-9693-23AB7686A456} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-57989841-746137067-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01EB5130-FC0C-4D75-B9CE-4801B1B854F5} -> Adware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-57989841-746137067-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{279A1B41-6CAC-4ABF-B39C-72C8E489F685} -> Adware.AdBlaster : Cleaned with backup
HKU\S-1-5-21-57989841-746137067-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01EB5130-FC0C-4D75-B9CE-4801B1B854F5} -> Adware.Begin2Search : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2296428D-C133-4928-B76A-A200FF409572} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{279A1B41-6CAC-4ABF-B39C-72C8E489F685} -> Adware.AdBlaster : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6001CDF7-6F45-471B-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95C60327-8E17-44D6-98EB-7EB70CC606DD} -> Adware.SafeSurfing : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5AF2622-8C75-4DFB-9693-23AB7686A456} -> Adware.Generic : Cleaned with backup
C:\WINDOWS\cpbrkpie.ocx -> Adware.Coupons : Cleaned with backup
C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@yadro[1].txt -> TrackingCookie.Yadro : Cleaned with backup
C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@www.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@www.web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Program Files\KaZaA\PerfectNavUninstall.exe -> Downloader.Keenval.e : Cleaned with backup
C:\Program Files\Network\network.exe -> Adware.Maxifiles : Cleaned with backup
C:\WINDXP\system32\b2search.exe -> Adware.EZula : Cleaned with backup
C:\WINDXP\system32\nsj4A.dll -> Adware.EZula : Cleaned with backup
C:\WINDXP\JUSTIN2.exe -> Adware.EZula : Cleaned with backup
C:\Documents and Settings\Stevo\Desktop\backups\backup-20060526-072138-893.dll -> Adware.PurityScan : Cleaned with backup
C:\Documents and Settings\Stevo\Desktop\backups\backup-20060526-072138-374.dll -> Adware.PurityScan : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
-> : Error during cleaning
:mozilla.22:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
-> : Error during cleaning
:mozilla.92:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
::Report End
PANDA log:
Incident Status Location
Adware:Adware/ShoppingCommunity Not disinfected C:\WINDOWS\SYSTEM\moconfig.exe
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@atwola[1].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[2].txt
Spyware:Cookie/WebPower Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@webpower[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[1].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[5].txt
Spyware:Cookie/Outster Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@outster[2].txt
Spyware:Cookie/Toplist Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@toplist[1].txt
Spyware:Cookie/WebPower Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@webpower[3].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\anyuser@desktop.kazaa[1].txt
Spyware:Cookie/Com.com Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@uol.com[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[9].txt
Spyware:Cookie/Xmts Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@xmts[1].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[6].txt
Spyware:Cookie/888 Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@888[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@ccbill[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[3].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[4].txt
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\anyuser@linkexchange[1].txt
Spyware:Cookie/Rn11 Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@rn11[1].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@desktop.kazaa[8].txt
Spyware:Cookie/Toplist Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@toplist[2].txt
Spyware:Cookie/WebPower Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@webpower[1].txt
Spyware:Cookie/Target Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@target[1].txt
Spyware:Cookie/TeensForCash Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@www.teensforcash[1].txt
Spyware:Cookie/Gorillanation Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@ads.gorillanation[1].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@atwola[2].txt
Spyware:Cookie/Com.com Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@www.netgate.com[1].txt
Spyware:Cookie/64.62.232 Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@64.62.232[1].txt
Spyware:Cookie/MyWay Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@www.xzoomy[1].txt
Spyware:Cookie/Santa Monica networks inc Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@smni[2].txt
Spyware:Cookie/Pollstar Not disinfected C:\WINDOWS\Profiles\stevo2k\Cookies\stevo@pollstar[2].txt
Adware:Adware/PurityScan Not disinfected C:\Program Files\Common Files\?ssembly\winspool.exe
Spyware:Spyware/LinkReplacer Not disinfected C:\Program Files\Jalmp\uninstall.exe
Hacktool:Flooder Program Not disinfected C:\old\TRiBE7\Tools\EF29.EXE
Spyware:Cookie/Cd Freaks Not disinfected C:\old\Recycled\NPROTECT\00071379.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070139.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070140.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070141.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070142.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070143.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070144.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070145.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070146.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070147.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070148.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070149.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070150.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070151.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070152.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070153.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070154.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070155.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070156.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070157.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070158.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070159.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070170.TXT
Spyware:Cookie/Go Not disinfected C:\old\Recycled\NPROTECT\00070171.TXT
Adware:Adware/SaveNow Not disinfected C:\old\Recycled\NPROTECT\00071182.EXE
Spyware:Spyware/Conducent-Timesink Not disinfected C:\old\Program Files\Crystal Art Software\Crystal FTP\TSUninstaller.exe
Spyware:Cookie/Hypercount Not disinfected C:\old\old2\RECYCLED\NPROTECT\00062963.TXT
Spyware:Cookie/LinkExchange Not disinfected C:\oldserver\WINDOWS\Cookies\stevo@linkexchange[1].txt
Spyware:Spyware/SafeSurf Not disinfected C:\WINDXP\system32\irsinst.exe[ExtractDLL.dll]
Spyware:Spyware/SafeSurf Not disinfected C:\WINDXP\system32\unirimon.exe
Adware:Adware/YazzleSudoku Not disinfected C:\WINDXP\system32\GS_SilentSudokuInstaller.exe[GS_SudokuInstaller.exe]
Adware:Adware/YazzleSudoku Not disinfected C:\WINDXP\system32\GS_SilentSudokuInstaller.exe[GS_SudokuInstaller.exe][Sudoku.exe]
Adware:Adware/IPInsight Not disinfected C:\WINDXP\inf\conscorr.inf
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINDXP\pf78.exe
Adware:Adware/ISearch Not disinfected C:\WINDXP\Downloaded Program Files\initial.inf
Adware:Adware/IST.YourSiteBar Not disinfected C:\WINDXP\Downloaded Program Files\ysbactivex.inf
Adware:Adware Program Not disinfected C:\WINDXP\Downloaded Program Files\WildApp.inf
Adware:adware/sidesearch Not disinfected C:\WINDXP\sepsd.bin
Spyware:application/bestoffer Not disinfected C:\WINDXP\smdat32m.sys
Adware:Adware/CommAd Not disinfected C:\WINDXP\U3RldmU\oal5xAo.vbs
Spyware:Spyware/MarketScore Not disinfected C:\WINDXP\rlvknlg.exe
Adware:adware/elitebar Not disinfected C:\WINDXP\eliteunstall.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Stevo\Local Settings\Temp\!update.exe
Adware:adware/zenosearch Not disinfected C:\Documents and Settings\Stevo\Start Menu\Programs\Startup\Zeno.lnk
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Stevo\Cookies\stevo@doubleclick[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Stevo\Cookies\stevo@z1.adserver[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Stevo\Cookies\stevo@stats1.reliablestats[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Stevo\Cookies\stevo@zedo[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Stevo\Cookies\stevo@adopt.hbmediapro[2].txt
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2f3daa29-7ffa0144.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2f3daa29-7ffa0144.zip[VB.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2f3daa29-7ffa0144.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2f3daa29-7ffa0144.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-77626e25-562ba50a.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-77626e25-562ba50a.zip[VB.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-77626e25-562ba50a.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-77626e25-562ba50a.zip[Beyond.class]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.doubleclick.net/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.paycounter.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.sexlist.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.sextracker.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[counter9.sextracker.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.atdmt.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.atwola.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Stevo\Application Data\Mozilla\Profiles\default\rlg8wfew.slt\cookies.txt[.realmedia.com/]
Adware:adware/tvmedia Not disinfected C:\Documents and Settings\Stevo\Application Data\tvmknwrd.dll
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\ar3.jar-3cd8601-64debc02.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\ar3.jar-3cd8601-64debc02.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\ar3.jar-3cd8601-64debc02.zip[VerifierBug.class]
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-14715262.zip[javainstaller/InstallerApplet.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\loaderadv569.jar-560641e0-4eda4d94.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\loaderadv569.jar-560641e0-4eda4d94.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\loaderadv569.jar-560641e0-4eda4d94.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Stevo\.jpi_cache\jar\1.0\loaderadv569.jar-560641e0-4eda4d94.zip[Parser.class]