Jump to content


- - - - -

More win32 problems


  • Please log in to reply
48 replies to this topic

#21 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 09:50 PM

And here is my HSlog:

Horseserver Removal Tool v1.05
by Atri
-
-
1. Registry Fix Started
-
Registry fix complete
-
2. Deleted Services
-
-
3. Finding files Located on system
-
tmp*.tmp
w32tm.exe
-
4. Deleting files that were found.
-
-
5. Checking for and Removing Winupdate
-
winupdate file found
-
WindowsUpdate

#22 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 09:53 PM

Here's my Hijack This log. It looks like windows 32 is still around (grrrr!). But my desktop and browser seem to be MUCH better (except for my disabled right-click). Thank you soooo much, and please tell me what to do next!

Logfile of HijackThis v1.99.1
Scan saved at 10:50:08 PM, on 9/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cox\Applications\app\Prism.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\cox\applications\app\CurtainsSysSvcNt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\AOL\1124573388\ee\AOLHostManager.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Common Files\AOL\1124573388\ee\AOLServiceHost.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\1124573388\ee\AOLServiceHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Desktop\ARIEL\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\AUserInit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - (no file)
O2 - BHO: Class - {BD9CF1BA-C149-7FD6-0BF4-CE2A97CF0E4F} - C:\WINDOWS\sdklz32.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {64634180-B0EA-48B6-82B7-9620D33362C1} - (no file)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124573388\ee\AOLHostManager.exe
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [MoneyAgent] C:\Program Files\Microsoft Money\System\mnyexpr.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing) (HKCU)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectk...flowActiveX.CAB
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\cox\applications\app\CurtainsSysSvcNt.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#23 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 09:55 PM

Can you add the Ewido report as an attachment
In your reply use the Browse button near the bottom
Navigate to the saved report and then right click on it and Select it
Then Add this Attachment button

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#24 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 10:23 PM

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:15:44 PM, 9/5/2005
+ Report-Checksum: 9F8940A6

+ Scan result:

HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{04CB6006-AB79-1366-4EF1-BFF815B874EE} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{09312E20-8C50-C241-742B-35F21EDA9875} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0ADD4D53-B7DD-20F8-2AC9-AB9CB538A46F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0B538AE6-8676-E13B-4CEC-E6A75F19F1EF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{15E6172A-5F7D-3085-1E94-14DA8D1A4479} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1F5650BA-2C95-0E8C-5C3F-D482646BF979} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1FE935FF-DB66-AC76-99D8-18EC1F0F013C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{29B25401-5964-022D-3AC2-C7207FEFF994} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{29CDA41A-A8EB-6A68-BBF5-2877418D55C7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2A6A2EFF-2FC6-683C-5911-BB1AC07E5964} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3A1550DD-FD7B-8D6E-989A-49A66DF1433F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3EA8A165-1EE8-2BEF-A8D1-9CDBD760FC43} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3F15B481-32E2-FE85-96FA-A8976289B4FD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{434236E6-77E0-412c-B45B-7E78E7F41E59} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{43F226F3-3EDD-1F6E-B1F9-426F80DAB07E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4E11A0FD-72A3-AEF3-D4E4-E168F75A238E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{52343DBF-CF46-B3EA-81BB-8A3DCB6B9A64} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{551764CC-ABCF-335C-76F6-62283B478A0F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5DA6CA48-7D98-BC0B-40EF-22AC6558668A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{62B52B4D-547B-BFC7-9850-79709FDECF27} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6327D790-4626-130D-8171-E0E6AB10B53B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{714C2287-DB2D-3514-4785-8EC21BA5C5F1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{735DDAC7-F8F1-47DD-D87A-6AF0100B6A48} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{765369C1-D4E0-D6A4-69B4-6261D4E1319A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7658C68E-7ED4-8476-AC96-729091012307} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{78CA5367-0660-D7DE-5424-C4AD26542538} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7A66D0FF-9707-2E41-A80D-7DE113BDAC8B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7A8EC00B-7964-C396-E2F8-621F6C9029FA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7DA446BF-5485-78F9-CC9A-2A02C93519E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8324D4AA-9FD0-5334-D040-C3B82F9A8957} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8669ABB2-7410-3460-F449-E119DCA24CC4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{86B29A5F-CB91-3C3D-28A2-EDA38C1F28A8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{877DBFE0-6233-B1C4-8252-A4475BCF6DD2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{92854EC1-0623-4E3A-3993-F60435FEDF74} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{952AA538-C1D7-30E5-8DC6-1A12E2F736A2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9913F006-5621-D9B4-E3CB-064477E8D278} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{99B1E639-DCA2-2C21-013F-DEF4B5729CA9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9C060FC3-F4CE-894D-8EB7-FA3935CE5AA1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9D7705A4-9543-9869-8249-F62AC961BDA5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A678B034-1492-1AC1-FF9B-636BC85F5643} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AEF3E64A-B4FC-FC2A-5EF9-4FC735F322D9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AF197E67-53B8-6C01-4733-3E7C25BA3A3B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B1169ABC-E367-2937-9F96-3B9CB54E0F31} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B36D5282-D413-F545-CF79-A6CE970CFEBB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B4F697AE-7E58-DC0D-D012-24F83EAB9F25} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B59A1E0B-4C94-AA3A-C37F-94C8BFC643E7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B7ABD257-6E0C-E7F0-26F5-0315127E44C2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C092CEA0-FB34-5E12-83ED-47942941DECC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C9368290-DE0B-80FF-0E2D-8933F6CA1A46} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D1F6B196-AB9F-2B48-C708-0B7CEC5DA4F9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D6063F46-66EC-A24F-FC65-2CF52E8C6A80} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DBC8BCC3-8C2E-707C-3D8D-72B88F17460E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DBE13E5D-7E11-2943-722B-C75B9A94EFED} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DE2D7676-D3B6-1EDB-60CA-DA72D6F9B006} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E5181BB3-B821-0D7B-D568-3766286D5460} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E8A06DEA-6626-407D-5720-FE211C989AC1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EF24BEB1-9592-9F8F-4B29-99399FD2C231} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EF4CB83E-BEF0-2DE3-F01E-55D0127FF3EA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1B10CDC-1975-EC0C-C522-2571525E92CF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F3B884B1-3181-A180-8EA9-B6E06DF7844E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F802FEC2-BF51-3198-4339-747CCF253651} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F99D5FC9-1F47-B6F5-F1D5-55AFEAD2853A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FC955BB2-DAA2-E394-1DD3-E8A207B823A6} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FDEDD1BB-EE5D-1AF2-C50B-11681C5E2A93} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{18E6C36A-C45F-4B60-A1A4-5C0BB16D4CC2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{00A322E2-7D50-4DBA-BEA4-5C8078D47269} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} -> Spyware.TotalVelocity : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-112DE11F7392717E1 -> TrojanDownloader.Agent.kf : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-112E236CDC526AB -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-11EB858FA40116F1A -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1481859F425257EB -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1481947A5E2A6328 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148194AB1191461B4 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1481A15D750E25E8D -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1481A51081F235C44 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1481B668A5A963DDD -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1482B6DD887A10E3 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1482C66E82EFC3041 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1482D780A35CC551E -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1482E257B16C7E9E -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1482E6BE02D57255D -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14833343F004CA6 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148341D7335D9644E -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1483529E03E53499B -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484B261FB95BEC -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484B50C1289F45D7 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484B65CBF1171C7 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484C36F913895C78 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484C37C15D4272FD -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484C5DC55D6CBD0 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484D1AC9134D13A8 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484D50ADA165DD1 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484D6CDEA48EDB -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484E19051ECD3681 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484E252812714374 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484E2C376C913F01 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484E62E0597155B8 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484F10B269FC1E40 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1484F3DC73E9D24B4 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485057BF43826587 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485078F25A6C5928 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148507967440B4B5E -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14850B8820CB33FC -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485177D825BD273D -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485178D6146CD8 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14851795E16FE3A06 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148522C2A534A1F24 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148523565DD03D02 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148523E1A66AC6156 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485325ECBF83364 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14853686A1F5270A7 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148536FE278C8248D -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14854328B32326C0 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485473C47CF74877 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148548C257AD538D -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148555B3C3C7D403E -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148555DE41CFE3D61 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148563682672352EE -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-14856478D7C9A28B4 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148566E6E774E627C -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148575AA05A4972EB -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1485E5A26290C66B5 -> Spyware.Spywad : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-148766B113D53D53 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-1488160C3446878 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E1414A5691A5FFA -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E15567139CF3380 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E167318663A4EF6 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E17466D63163BF0 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E177CE24F892F0C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E18423D4B845F14 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E192E315B765BDC -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E1A39F419E24391 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E1B421A4BA43795 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E1C121E7F81384C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E2022EA5C451C8B -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E21EAC379676E4 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-3E2262AC1A241B78 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-40104A136EC55CF8 -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-4058586E36A054B4 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-466E68801AF2122A -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-4790790376D41E1C -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-47921E31345846AC -> TrojanDownloader.Agent.kf : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-479349416CBE7886 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-4839A616D555305 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-483E6E1D506246EE -> Trojan.Agent.em : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-484A634963F4D57 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-485520396FB2CA0 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-485F45F613083896 -> Trojan.Agent.em : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-486319AE191A6AC7 -> TrojanDownloader.Small.azk : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-487D5DCE446469B3 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-4882269941707467 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-488368E81B212D62 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-488573FD3FF134B4 -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-B7EA25A57A166103 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-B7EF37586B1D238E -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-BFB416F71EB43999 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F19DA2CB8B88 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F240798A02870 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F250D233C66A50 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F3583F32F91C48 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F433606FB36BB5 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F44BFB71FE787A -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F564246B1C404D -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F57C9D73196C07 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F65A7D36AF39CF -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F721666FBE6D4F -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F852AA40747595 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F952B25DCED32 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9F964EE24162B77 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FA3DF676894B67 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FA7EE31FD46354 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FB48FC73C940B3 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FB49FB56275190 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FC378D54F769F -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FC6BFC4EE36E7 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FD22BA71ED443 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FD25723182565D -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FE449C3B62A9B -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-C9FF1A662AB512A5 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0052FA645A735C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA007E395953283E -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA00840373B32D9 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0114E67CAB384A -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0124821ACB3F25 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA021471457837A8 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA035359B45EAC -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA039337452BAE -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA044F327860553E -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA047B1469D7396C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0537C8287337B1 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA056D5D70D97ACA -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA064AD855292FC3 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA065E395CE758E -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA066B502E9F7ABD -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA076C464DE55E6B -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA084C1221B511C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA096D115877209 -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0A611A22E5250E -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0A7A685F672E18 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0B33A05FC5120 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0B401722651937 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0C63B1402C160B -> Spyware.SearchPage : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0D525C186B10A1 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0D6A9D225232DD -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA0F20FE7CE55A0F -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA1127D066F0286C -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA116444620315C1 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA117F4D60B1624A -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA1215D2722EEEC -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA124BB12E7F102A -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA1250630EE5B7 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA131B2A6736689A -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA14BB224C06ABB -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA171D3950684EF8 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA1722D9708E365 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA183BF17AD01BF3 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA184EF7781D10E2 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA1861FF14822354 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA193748213B786 -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\NCJEGHUW6GRB\VirusBin\Infected-CA19604B4A