Ewido log, part 1
I had to do this in 2 parts as I had to be interrupted the first time to work. Here is the log of the first scan:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:14:52 PM 8/8/2006
+ Scan result:
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\63CTOXI7\jemhgfdcb[1].txt -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255257.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255296.DLL -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255348.DLL -> Adware.BHO : Cleaned with backup (quarantined).
HKLM\SOFTWARE\DSI -> Adware.Delfin : Cleaned with backup (quarantined).
HKU\S-1-5-21-891307005-429115175-1203367206-1005\Software\DSI -> Adware.Delfin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\relatedlinks -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\110354.exe -> Dialer.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Application Data\f0a938af.exe -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\63CTOXI7\bmlgjeg[1].txt -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255294.EXE -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255295.EXE -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255346.EXE -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255347.EXE -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\WINDOWS\system32\f0a938af.exe -> Downloader.Obfuscated.n : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Application Data\ddf30f0a.exe -> Downloader.Small.csn : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IPWXGZ6P\mazedlwi[1].txt -> Downloader.Small.csn : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ddf30f0a.exe -> Downloader.Small.csn : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IPWXGZ6P\bwitsrqbw[1].txt -> Downloader.Small.ctf : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\phpxi[1].txt -> Downloader.Small.cux : Cleaned with backup (quarantined).
C:\Program Files\Internet Explorer\Iesearch.exe -> Dropper.Small.gd : Cleaned with backup (quarantined).
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Temporary Internet Files\Content.IE5\9LCUJFHX\cVhsVXJrVXl0Sm9BQUd0YVRMOEFBQUJt[1].wmf -> Exploit.MS05-053-WMF : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IPWXGZ6P\lgonvkw[1].txt -> Hijacker.Small.kr : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\63CTOXI7\dlteqco[1].txt -> Hijacker.StartPage.adi : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\upbwlxiu[1].txt -> Hijacker.StartPage.adi : Cleaned with backup (quarantined).
C:\Program Files\ryads.exe -> Hijacker.StartPage.adi : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\ckflieqxm[1].txt -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\plfeqcamh[1].txt -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255254.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255293.EXE -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255345.EXE -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4J6ZAN4J\ksemkwvucn[1].txt -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4J6ZAN4J\kwvgb[1].txt -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255255.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255256.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.14:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@www.burstbeacon[3].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@burstnet[4].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@www.burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@casalemedia[3].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@com[2].txt -> TrackingCookie.Com : Cleaned.
:mozilla.13:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wfk4uhcpceo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wfk4ukdpibo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wjkoupdjgcp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wjkyckcpwao.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wjlioidzslp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@e-2dj6wjnyopdjigp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4kidpacoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyeiajglpwudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4cocpmdqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliwoc5whpwsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyugazgfpaudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmicmc5aapgqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@adopt.euroclick[3].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@server.iad.liveperson[3].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.43:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.44:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.15:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.16:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.17:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.18:C:\Documents and Settings\Lori Watson\Application Data\Mozilla\Profiles\default\jwhqzzsb.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@serving-sys[3].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@adopt.specificclick[3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@statcounter[3].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Cookies\lori
watson@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Lori Watson\Local Settings\Temp\Temporary Internet Files\Content.IE5\2PG3KNYF\runapl[1].exe -> Trojan.LowZones.df : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4J6ZAN4J\jrdpnmyk[1].htm -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IPWXGZ6P\rzutsdcx[1].htm -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\dlgsq[1].txt -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\dpkjvts[1].txt -> Trojan.Regger.s : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LFRNNMQ2\rzhtsdpb[1].txt -> Trojan.Sinowal.ae : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00009.dll -> Trojan.Sinowal.ae : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00010.dll -> Trojan.Sinowal.ae : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00009.exe -> Trojan.Sinowal.ai : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255251.exe -> Trojan.Sinowal.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255252.dll -> Trojan.Sinowal.m : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\63CTOXI7\ponvgqnxql[1].txt -> Trojan.Sinowal.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255291.DLL -> Trojan.Sinowal.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1206\A0255292.DLL -> Trojan.Sinowal.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255343.dll -> Trojan.Sinowal.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3516953C-55A1-48BF-94AE-4D0884B964C6}\RP1208\A0255344.dll -> Trojan.Sinowal.v : Cleaned with backup (quarantined).
C:\WINDOWS\system32\restore.exe -> Trojan.SubSearch.d : Cleaned with backup (quarantined).
::Report end