Hi
Please find below :
The AVG Report
the new Combofix log
a new HijackThis log
My feelings about Internet Explorer behavior will come later.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:04:56 AM 9/20/2007
+ Scan result:
D:\CIMAGE\PROGRA~1\BARGAI~1\BBCHK.EXE -> Adware.BargainBuddy : Cleaned with backup (quarantined).
D:\CIMAGE\PROGRA~1\BARGAI~1\BIN\BARGAINS.EXE -> Adware.BargainBuddy : Cleaned with backup (quarantined).
D:\Download\mailmoa3.exe/cd_clint.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
D:\Download\mailmoa3.exe/cd_load.exe -> Adware.Cydoor : Cleaned with backup (quarantined).
D:\Download\mailmoa3.exe/cd_swf.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
D:\CIMAGE\PROGRA~1\EXACT\EXACTT~2.DLL -> Adware.Exact : Cleaned with backup (quarantined).
D:\CIMAGE\PROGRA~1\EBATES~1\SYSTEM\CODE\BF~2.CLA -> Adware.MoeMoney : Cleaned with backup (quarantined).
D:\CIMAGE\PROGRA~1\EBATES~1\SYSTEM\CODE\BS~2.CLA -> Adware.MoeMoney : Cleaned with backup (quarantined).
D:\CIMAGE\WINDOWS\NEWDOT~1.DLL -> Adware.NewDotNet : Cleaned with backup (quarantined).
D:\Download\MsgPlus-301.exe/Sponsor.exe -> Downloader.Swizzor.bt : Cleaned with backup (quarantined).
D:\CIMAGE\PROGRA~1\ENCOMP~1\ENCDIAL.EXE -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP706\A0108751.DLL -> Logger.Agent.rt : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.a : Cleaned with backup (quarantined).
D:\CIMAGE\WINDOWS\COOKIES\DEFA~499.TXT -> TrackingCookie.2o7 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~950.TXT -> TrackingCookie.2o7 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1111.TXT -> TrackingCookie.2o7 : Cleaned.
D:\Documents\Noa\Old Noa\Cookies\noa@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~874.TXT -> TrackingCookie.7search : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~648.TXT -> TrackingCookie.Ad-flow : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1071.TXT -> TrackingCookie.Ad-flow : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~807.TXT -> TrackingCookie.Ad-logics : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~481.TXT -> TrackingCookie.Addynamix : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~575.TXT -> TrackingCookie.Adorigin : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~243.TXT -> TrackingCookie.Adserver : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~578.TXT -> TrackingCookie.Adserver : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~774.TXT -> TrackingCookie.Adserver : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~732.TXT -> TrackingCookie.Adtech : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~251.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~308.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~415.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~688.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~944.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1146.TXT -> TrackingCookie.Advertising : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~31.TXT -> TrackingCookie.Atdmt : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~75.TXT -> TrackingCookie.Atdmt : Cleaned.
D:\Documents\Noa\Old Noa\Cookies\noa@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~56.TXT -> TrackingCookie.Bfast : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~806.TXT -> TrackingCookie.Bfast : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~120.TXT -> TrackingCookie.Bluemountain : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~198.TXT -> TrackingCookie.Bluemountain : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~27.TXT -> TrackingCookie.Bluestreak : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~108.TXT -> TrackingCookie.Bluestreak : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~266.TXT -> TrackingCookie.Bluestreak : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~288.TXT -> TrackingCookie.Bluestreak : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~376.TXT -> TrackingCookie.Bluestreak : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~50.TXT -> TrackingCookie.Bpath : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~460.TXT -> TrackingCookie.Bpath : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1162.TXT -> TrackingCookie.Bpath : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~426.TXT -> TrackingCookie.Bridgetrack : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~649.TXT -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.289:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~430.TXT -> TrackingCookie.Centrport : Cleaned.
D:\Documents\Noa\Old Noa\Cookies\noa@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~614.TXT -> TrackingCookie.Clickagents : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~163.TXT -> TrackingCookie.Clickzs : Cleaned.
:mozilla.394:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~687.TXT -> TrackingCookie.Co : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~134.TXT -> TrackingCookie.Com : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~19.TXT -> TrackingCookie.Comclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~301.TXT -> TrackingCookie.Comclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~344.TXT -> TrackingCookie.Commission-junction : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~638.TXT -> TrackingCookie.Commission-junction : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~892.TXT -> TrackingCookie.Commission-junction : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1001.TXT -> TrackingCookie.Commission-junction : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~295.TXT -> TrackingCookie.Coremetrics : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~54.TXT -> TrackingCookie.Counted : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~741.TXT -> TrackingCookie.Counted : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~505.TXT -> TrackingCookie.Dbbsrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~843.TXT -> TrackingCookie.Dealtime : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~988.TXT -> TrackingCookie.Dealtime : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~273.TXT -> TrackingCookie.Doubleclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~821.TXT -> TrackingCookie.Enliven : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~234.TXT -> TrackingCookie.Estat : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAUL~9.TXT -> TrackingCookie.Euniverseads : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1059.TXT -> TrackingCookie.Falkag : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1196.TXT -> TrackingCookie.Falkag : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~33.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~228.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~297.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~617.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~713.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~812.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~872.TXT -> TrackingCookie.Fastclick : Cleaned.
D:\Documents\Noa\Old Noa\Cookies\noa@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~832.TXT -> TrackingCookie.Findwhat : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUSE~6.TXT -> TrackingCookie.Fortunecity : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~49.TXT -> TrackingCookie.Fortunecity : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~289.TXT -> TrackingCookie.Fortunecity : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~698.TXT -> TrackingCookie.Fortunecity : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~935.TXT -> TrackingCookie.Fortunecity : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~961.TXT -> TrackingCookie.Gamershell : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~18.TXT -> TrackingCookie.Gator : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~309.TXT -> TrackingCookie.Gator : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~385.TXT -> TrackingCookie.Gator : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~500.TXT -> TrackingCookie.Gator : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~740.TXT -> TrackingCookie.Gator : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~298.TXT -> TrackingCookie.Goclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~98.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~99.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~220.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~285.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~347.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~378.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~380.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~454.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~471.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~618.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~651.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~654.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~693.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~751.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~794.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~845.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~891.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1123.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1148.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1165.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1197.TXT -> TrackingCookie.Hitbox : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~488.TXT -> TrackingCookie.Hitslink : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~898.TXT -> TrackingCookie.Hitslink : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~237.TXT -> TrackingCookie.Hotlog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~495.TXT -> TrackingCookie.Hotlog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1113.TXT -> TrackingCookie.Hotlog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~312.TXT -> TrackingCookie.Hyperbanner : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~492.TXT -> TrackingCookie.Hyperbanner : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~645.TXT -> TrackingCookie.Hyperbanner : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1163.TXT -> TrackingCookie.Hyperbanner : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1046.TXT -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.490:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.491:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.392:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Info : Cleaned.
:mozilla.410:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Info : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~846.TXT -> TrackingCookie.Internetfuel : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~659.TXT -> TrackingCookie.Liveperson : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1198.TXT -> TrackingCookie.Liveperson : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~113.TXT -> TrackingCookie.Mediaplex : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~192.TXT -> TrackingCookie.Mediaplex : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~719.TXT -> TrackingCookie.Mediaplex : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1160.TXT -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.210:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.224:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.237:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.239:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~722.TXT -> TrackingCookie.Msn : Cleaned.
D:\Documents\Noa\Old Noa\Cookies\noa@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~587.TXT -> TrackingCookie.Myaffiliateprogram : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~890.TXT -> TrackingCookie.Myaffiliateprogram : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~483.TXT -> TrackingCookie.Navrcholu : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~825.TXT -> TrackingCookie.Overture : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~287.TXT -> TrackingCookie.Paypal : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1038.TXT -> TrackingCookie.Paypopup : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1040.TXT -> TrackingCookie.Paypopup : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1041.TXT -> TrackingCookie.Paypopup : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1044.TXT -> TrackingCookie.Paypopup : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~852.TXT -> TrackingCookie.Pointroll : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~442.TXT -> TrackingCookie.Popupsponsor : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~581.TXT -> TrackingCookie.Popupsponsor : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~798.TXT -> TrackingCookie.Popupsponsor : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1015.TXT -> TrackingCookie.Popupsponsor : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~300.TXT -> TrackingCookie.Popuptraffic : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~571.TXT -> TrackingCookie.Popuptraffic : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1164.TXT -> TrackingCookie.Popuptraffic : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~16.TXT -> TrackingCookie.Pro-market : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~121.TXT -> TrackingCookie.Pro-market : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~339.TXT -> TrackingCookie.Pro-market : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~675.TXT -> TrackingCookie.Pro-market : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1203.TXT -> TrackingCookie.Pro-market : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~57.TXT -> TrackingCookie.Qksrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~275.TXT -> TrackingCookie.Qksrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~696.TXT -> TrackingCookie.Qksrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1108.TXT -> TrackingCookie.Qksrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1110.TXT -> TrackingCookie.Qksrv : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~131.TXT -> TrackingCookie.Questionmarket : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~425.TXT -> TrackingCookie.Questionmarket : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~841.TXT -> TrackingCookie.Questionmarket : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~147.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~244.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~245.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~314.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~565.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~921.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~922.TXT -> TrackingCookie.Real : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUSE~3.TXT -> TrackingCookie.Realmedia : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~93.TXT -> TrackingCookie.Realmedia : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~155.TXT -> TrackingCookie.Realmedia : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~956.TXT -> TrackingCookie.Realmedia : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~217.TXT -> TrackingCookie.Realtracker : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~776.TXT -> TrackingCookie.Realtracker : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~905.TXT -> TrackingCookie.Realtracker : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~936.TXT -> TrackingCookie.Realtracker : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1016.TXT -> TrackingCookie.Revenue : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~530.TXT -> TrackingCookie.Ru4 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~795.TXT -> TrackingCookie.Ru4 : Cleaned.
:mozilla.87:C:\Documents and Settings\Oved\Application Data\Mozilla\Firefox\Profiles\4nlo95o6.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~359.TXT -> TrackingCookie.Specificpop : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~101.TXT -> TrackingCookie.Spylog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~269.TXT -> TrackingCookie.Spylog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~639.TXT -> TrackingCookie.Spylog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~739.TXT -> TrackingCookie.Spylog : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~221.TXT -> TrackingCookie.Targetnet : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~590.TXT -> TrackingCookie.Targetnet : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~823.TXT -> TrackingCookie.Targetnet : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~981.TXT -> TrackingCookie.Tradedoubler : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~23.TXT -> TrackingCookie.Trafficmp : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~319.TXT -> TrackingCookie.Trafficmp : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~529.TXT -> TrackingCookie.Trafficmp : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~745.TXT -> TrackingCookie.Trafficmp : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~910.TXT -> TrackingCookie.Trafic : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~66.TXT -> TrackingCookie.Tribalfusion : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~274.TXT -> TrackingCookie.Tribalfusion : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~281.TXT -> TrackingCookie.Tribalfusion : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~540.TXT -> TrackingCookie.Tribalfusion : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~404.TXT -> TrackingCookie.Valuead : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~573.TXT -> TrackingCookie.Valuead : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~47.TXT -> TrackingCookie.Valueclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~151.TXT -> TrackingCookie.Valueclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~568.TXT -> TrackingCookie.Valueclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1151.TXT -> TrackingCookie.Valueclick : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~640.TXT -> TrackingCookie.Web-stat : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\ANYUS~30.TXT -> TrackingCookie.Weborama : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1185.TXT -> TrackingCookie.Weborama : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~200.TXT -> TrackingCookie.Webtrendslive : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFAU~18.TXT -> TrackingCookie.X10 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~218.TXT -> TrackingCookie.X10 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~691.TXT -> TrackingCookie.X10 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~767.TXT -> TrackingCookie.X10 : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~964.TXT -> TrackingCookie.Yadro : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEFA~704.TXT -> TrackingCookie.Zedo : Cleaned.
D:\CIMAGE\WINDOWS\COOKIES\DEF~1133.TXT -> TrackingCookie.Zedo : Cleaned.
D:\CIMAGE\WINDOWS\TEMPOR~1\CONTENT.IE5\P97N1D8Q\PUP_1_~1.HTM -> Trojan.NoClose.c : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119442.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\sysc10trg.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gdk.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\plugin0707.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\skypemsng.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\system32\updserv32.exe.vir -> Trojan.Small : Cleaned with backup (quarantined).
D:\Moved\Win98tmp\win98\Ena\WIN98_37.CAB/notepad.exe -> Worm.Volag.c : Cleaned with backup (quarantined).
D:\Moved\Win98tmp\win98\Loc\WIN98_37.CAB/notepad.exe -> Worm.Volag.c : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dbghd3dx.exe -> Worm.Warezov : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cnnperf.exe -> Worm.Warezov.mg : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cnnprf32.dll -> Worm.Warezov.mg : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dcon321.dll -> Worm.Warezov.mg : Cleaned with backup (quarantined).
C:\WINDOWS\system32\diagisr.dll -> Worm.Warezov.mo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\isrprf32.dll -> Worm.Warezov.mo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\isrprov.exe -> Worm.Warezov.mo : Cleaned with backup (quarantined).
[1260] C:\WINDOWS\system32\diagisr.dll -> Worm.Warezov.mo : Cleaned with backup (quarantined).
[3668] C:\WINDOWS\system32\diagisr.dll -> Worm.Warezov.mo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\con321.dll -> Worm.Warezov.nm : Cleaned with backup (quarantined).
C:\WINDOWS\system32\con321.exe -> Worm.Warezov.nm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119444.exe -> Worm.Warezov.og : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\system32\msngr.exe.vir -> Worm.Warezov.og : Cleaned with backup (quarantined).
C:\WINDOWS\mcngsk22.exe -> Worm.Warezov.ou : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP698\A0106509.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP701\A0106589.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP701\A0106604.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107607.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107624.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107634.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP703\A0107647.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP703\A0107665.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP703\A0107689.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP704\A0107698.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP704\A0107720.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP705\A0108721.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP706\A0108740.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP706\A0108754.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP706\A0109751.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP706\A0109761.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP710\A0109928.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP710\A0110929.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP711\A0111928.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP711\A0111939.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP711\A0112939.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0113235.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0113243.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114243.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114253.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114260.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114276.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114286.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114315.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114328.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP714\A0114348.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP715\A0115364.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP715\A0116364.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP715\A0116378.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP716\A0116411.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP718\A0117413.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP718\A0118418.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP718\A0119417.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119443.DLL -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119455.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119545.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0120555.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0120565.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0121564.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0122565.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msimtxl.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\WINDOWS\system32\winfpgpc.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\WINDOWS\system32\winfpgpc.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\system32\e1.dll.vir -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1028] C:\WINDOWS\System32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1160] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1280] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1356] C:\WINDOWS\System32\winfpgpc.exe -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1384] C:\WINDOWS\System32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1524] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1660] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1700] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1724] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1740] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1864] C:\WINDOWS\System32\msimtxl.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[1944] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[228] C:\WINDOWS\System32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[2980] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[464] C:\WINDOWS\System32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[544] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[556] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[580] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[588] C:\WINDOWS\System32\msimtxl.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[608] C:\WINDOWS\system32\winfpgpc.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[656] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[668] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[684] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[760] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[828] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
[892] C:\WINDOWS\system32\webhsbe.dll -> Worm.Warezov.pi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107618.exe -> Worm.Warezov.pk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107620.exe -> Worm.Warezov.pk : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sk070725.exe -> Worm.Warezov.ps : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP698\A0106504.exe -> Worm.Warezov.ra : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP719\A0119440.exe -> Worm.Warezov.re : Cleaned with backup (quarantined).
C:\qoobox\Quarantine\C\WINDOWS\system32\ss.exe.vir -> Worm.Warezov.re : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107601.exe -> Worm.Warezov.rf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{81EA1667-4F2F-4068-8DD3-B891AB90278C}\RP702\A0107619.exe -> Worm.Warezov.rh : Cleaned with backup (quarantined).
::Report end
ComboFix 07-09-18.4 - "Oved" 2007-09-20 0:17:32.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1255.972.1033.18.148 [GMT 2:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\confcnn.dll
.
((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.
2007-09-20 00:08 8,192 --a------ C:\WINDOWS\system32\dbghd3dx.exe
2007-09-19 20:56 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-19 17:38 <DIR> d--hs---- C:\FOUND.008
2007-09-18 18:48 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-18 15:33 <DIR> d--hs---- C:\FOUND.007
2007-09-18 14:34 62,976 --a------ C:\WINDOWS\system32\zddbg32.exe
2007-09-11 02:48 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-09-09 21:19 <DIR> d--hs---- C:\FOUND.006
2007-09-08 16:42 218 --a------ C:\WINDOWS\system32\cdbg32.exexe.exe
2007-09-08 14:41 124,444 --a------ C:\WINDOWS\system32\stdex32.exe
2007-09-01 22:40 26 --a-s---- C:\WINDOWS\system32\dasrep.dat
2007-08-31 16:31 0 --a------ C:\WINDOWS\jdqlxr8.dll
2007-08-31 16:07 37,195 --a------ C:\WINDOWS\system32\hac2.exe
2007-08-31 15:05 16 --a------ C:\WINDOWS\gfr.dat
2007-08-30 17:37 0 --a------ C:\WINDOWS\c8db5ntkl.dll
2007-08-27 14:02 127,597 --a------ C:\WINDOWS\system32\netdex.exe
2007-08-27 12:22 0 --a------ C:\WINDOWS\lov1co.dat
2007-08-24 15:54 98,304 --a------ C:\WINDOWS\system32\oserv25.dll
2007-08-24 15:54 9,216 --a------ C:\WINDOWS\system32\oservmc25.dll
2007-08-24 15:54 79,667 --a------ C:\WINDOWS\system32\oserv25.exe
2007-08-24 15:54 6,144 --a------ C:\WINDOWS\system32\oservmx25.exe
2007-08-24 15:54 16,384 --a------ C:\WINDOWS\system32\oservmz25.dll
2007-08-23 19:30 84,992 --a------ C:\WINDOWS\system32\Dennt.exe
2007-08-23 19:30 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-08-23 19:29 741,376 --a------ C:\WINDOWS\system32\libeay32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-08-17 14:32 45056 --ah----- C:\WINDOWS\system32\sperf.exe
2007-08-08 03:48 114176 --a------ C:\WINDOWS\system32\pk32j.exe
2007-08-05 01:02 --------- d-------- C:\DOCUME~1\OVED\APPLIC~1\SPAMfighter
2007-07-24 08:50 61440 --ah----- C:\WINDOWS\system32\h2ubcjsw.dll
2007-07-24 08:50 53248 --ah----- C:\WINDOWS\system32\ewph65as.dll
2007-07-24 08:50 45056 --ah----- C:\WINDOWS\system32\bwxlno9a1p.exe
2007-07-12 18:44 65536 --ah----- C:\WINDOWS\system32\onfksd.dll
2007-07-12 18:44 53248 --ah----- C:\WINDOWS\system32\sdprf32.dll
2007-07-12 18:44 462848 --ah----- C:\WINDOWS\system32\ksdmgr32.dll
2007-07-12 18:44 45056 --ah----- C:\WINDOWS\system32\sdperf.exe
2007-07-12 18:44 217088 --ah----- C:\WINDOWS\system32\ksstat.dll
2007-07-06 13:50 87921 --a------ C:\WINDOWS\system32\servsq.exe
2007-07-04 14:22 1184400 --a------ C:\WINDOWS\system32\FreeImage.dll
2004-10-01 15:00 40960 --a------ C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot_2007-09-18_185929.86 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 163,328 2007-03-13 08:57:12 C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="D:\Programs\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"LGODDFU"="D:\Programs\lg_fwupdate\fwupdate.exe" [2006-02-20 11:40]
"himem.exe"="C:\WINDOWS\system32\stdex32.exe" [2007-09-08 14:42]
"SoundMnEx32"="C:\WINDOWS\system32\svvhost.exe" []
"ksddi"="C:\WINDOWS\system32\kconf.exe" []
"Sund32"="C:\WINDOWS\system32\Dennt.exe" [2007-08-23 19:30]
"oserv25"="C:\WINDOWS\System32\oserv25.exe" [2007-09-20 00:24]
"hac2"="C:\WINDOWS\system32\hac2.exe" [2007-08-31 16:07]
"reganal32"="C:\WINDOWS\system32\reganal32.exe" []
"regstd"="C:\WINDOWS\system32\regstd.exe" []
"Hacdbg32"="C:\WINDOWS\system32\Hacdbg32.exe" []
"stdex32"="C:\WINDOWS\system32\stdex32.exe" [2007-09-08 14:42]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"zddbg32"="C:\WINDOWS\system32\zddbg32.exe" [2007-09-18 14:34]
"!AVG Anti-Spyware"="D:\Programs\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 13:56]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2006-02-10 21:40]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - D:\Programs\Microsoft Office 2000\Office\OSA9.EXE [1999-02-17 22:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ksdmgr]
ksdmgr32.dll 2007-07-12 18:44 462848 C:\WINDOWS\system32\ksdmgr32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\oserv25]
C:\WINDOWS\System32\oserv25.dll 2007-08-24 15:54 98304 C:\WINDOWS\system32\oserv25.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winfpgpc]
C:\WINDOWS\system32\winfpgpc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"= webhsbe.dll e1.dll confcnn.dll onfksd.dll ksstat.dll h2ubcjsw.dll oservmz25.dll diagisr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Oved^Start Menu^Programs^Startup^WinMySQLadmin.lnk]
path=C:\Documents and Settings\Oved\Start Menu\Programs\Startup\WinMySQLadmin.lnk
backup=C:\WINDOWS\pss\WinMySQLadmin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
"D:\Programs\ICQLite\ICQLite.exe" -minimize
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
D:\Programs\OLYMPUS\OLYMPUS Master\FirstStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"D:\Programs\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
"D:\Programs\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
R2 LANPkt;Realtek LANPkt Protocol;C:\WINDOWS\system32\DRIVERS\LANPkt.sys
R2 ONSIO;ONSIO;\??\C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS
R3 admjoy;Aureal Game Port Enumerator;C:\WINDOWS\system32\DRIVERS\admjoy.sys
R3 METROP;Hewlett Packard ScanJet 5300C;C:\WINDOWS\system32\DRIVERS\hp53pw2k.sys
R3 mf;mf;C:\WINDOWS\system32\DRIVERS\mf.sys
R3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINDOWS\system32\drivers\adm8830.sys
S0 SMPLSCSI;SMPLSCSI;C:\WINDOWS\system32\drivers\SMPLSCSI.SYS
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-20 00:26:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-20 0:30:55 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-20 00:30
C:\ComboFix2.txt ... 2007-09-18 19:00
.
--- E O F ---
????
????? ??????? ??? ??????
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
AVG Anti-Spyware 7.5
Chavruta
Coup de Pouce Lecture CP-CE1 v1.0
DivX
DoroTree
DVD Solution
FormServer
Free Download Manager 2.0 - Free Downloads Center Edition
Frontbase Image To Icon 2.1
Harry Potter II
Hijackthis 1.99.1
HijackThis 1.99.1
hp deskjet 5550 series (Remove only)
HP PrecisionScan
hp print screen utility
ICQ6
LAN Utility
LG ODD Auto Firmware Update
Microsoft Office 2000 Small Business
Microsoft Office Professional Edition 2003
Microsoft Office Standard Edition 2003
MSN
MSXML 4.0 SP2 (KB927978)
Nero OEM
OLYMPUS Master
PowerDVD
PowerProducer
Presto! PageManager
RealPlayer
RollerCoaster Tycoon 2
SCANPORT ScanModule V2.43
Scooby-Doo (TM), Le Myst?re du Ch?teau hant?(TM)
Scooby-Doo(TM), Panique dans la Ville fant?me(TM)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Skype 2.5
The Gabay
upapp
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
USB PC Camera 301P
VideoLAN VLC media player 0.8.5
VoipBuster
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
WinZip
Xvid 1.1.2 final uninstall