I'm new to virsus removal processes. It seems very interesting. I need help to complete the removal of the xorpix trojan virus.
Steps already taken:
1 - SpyBot scan - but cannot remove this particular virus
2 - ewido scanned - but cannot remove this virus.
3 - HiJackThis ran - I don't know what to remove
4 - KillBox downloaded - I don't know what files to select and kill.
Also, a file with the name is unremovable(delete it and it immmedialty reappear) is it artm_new - can't find any artm.dll files anywhere.
Any help would be greatly appreciated.
Thank You
iastin
// --------- Log file from ewido-----------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:43:29 PM 9/9/2006
+ Scan result:
C:\Documents and Settings\Ike\198_150_ni_7.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\xLSMNTTYGFK.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3164941679-1693736371-1378865824-1005\Dc1.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\198_150_ni_7.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\xLTSTOSWUOP.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\xQDTWGTSOAD.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_2[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_5[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[3].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_2[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_3[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_4[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_4[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_5[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_7[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_7[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_1[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_1[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_7[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dktibs.exe -> Downloader.Delf.dc : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hlink.exe -> Downloader.Reqlook.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP334\A0169880.exe -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016790.EXE -> Downloader.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016962.EXE -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166451.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166474.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167820.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167821.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dxmasf.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\kbdcz.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mfc70esp.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\txflog.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\usbui.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\samicro.dll -> Downloader.Small.bxh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP334\A0169876.dll -> Downloader.Small.byd : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\5.dlb -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016784.EXE -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166449.exe -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016977.EXE -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166485.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\testtestt.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016983.EXE -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166491.exe -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016143.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016151.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016152.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016965.EXE -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166478.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167836.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dxvwhmts.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\6.dlb -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\7.dlb -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016778.EXE -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016781.EXE -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166447.exe -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166448.exe -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016968.EXE -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166480.exe -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\WINDOWS\exact.exe -> Dropper.Small.aox : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\82.tmp -> Hijacker.Costrat.l : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temporary Internet Files\Content.IE5\456JKLYZ\winmad2[1].exe -> Hijacker.Costrat.l : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016959.EXE -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3164941679-1693736371-1378865824-1006\Dc55.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166472.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\stonedrv.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\art7063.tmp -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016971.EXE -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166481.exe -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\artAD9.tmp -> Proxy.Xorpix.al : Error during cleaning.
C:\Documents and Settings\Ike\Cookies\ike@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@www.epilot[2].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@c.goclick[2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\ike@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\NPROTECT\00017399.dll -> Trojan.Agent.fc : Cleaned with backup (quarantined).
C:\WINDOWS\jaaste.dll -> Trojan.Agent.fc : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\ughgcfwa.exe -> Trojan.Agent.pk : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temporary Internet Files\Content.IE5\456JKLYZ\2236[1].exe -> Trojan.Agent.pk : Cleaned with backup (quarantined).
C:\WINDOWS\assest.dll -> Trojan.Dialer.bi : Cleaned with backup (quarantined).
C:\WINDOWS\sasent.dll -> Trojan.Dialer.bi : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00017060.EXE -> Trojan.Dialer.pw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166536.exe -> Trojan.Dialer.pw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00017036.EXE -> Trojan.Killav.db : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166525.exe -> Trojan.Killav.db : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\msn.exe -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.dll -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167824.EXE -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\2.dlb -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016787.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016974.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016980.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016986.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016989.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016992.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166450.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166483.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166488.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166496.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166498.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166502.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
//---- end ewido
Steps already taken:
1 - SpyBot scan - but cannot remove this particular virus
2 - ewido scanned - but cannot remove this virus.
3 - HiJackThis ran - I don't know what to remove
4 - KillBox downloaded - I don't know what files to select and kill.
Also, a file with the name is unremovable(delete it and it immmedialty reappear) is it artm_new - can't find any artm.dll files anywhere.
Any help would be greatly appreciated.
Thank You
iastin
// --------- Log file from ewido-----------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:43:29 PM 9/9/2006
+ Scan result:
C:\Documents and Settings\Ike\198_150_ni_7.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\xLSMNTTYGFK.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3164941679-1693736371-1378865824-1005\Dc1.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\198_150_ni_7.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\xLTSTOSWUOP.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\xQDTWGTSOAD.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_2[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_5[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8PE7OHEF\200_160_i_6[3].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_2[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_3[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_4[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_4[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_5[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_7[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YH0JK3MW\200_160_i_7[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_1[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_1[2].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_3[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Z0J2CMNO\200_160_i_7[1].abc -> Downloader.Agent.wd : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dktibs.exe -> Downloader.Delf.dc : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hlink.exe -> Downloader.Reqlook.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP334\A0169880.exe -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016790.EXE -> Downloader.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016962.EXE -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166451.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166474.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167820.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167821.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dxmasf.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\kbdcz.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mfc70esp.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\txflog.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\usbui.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\samicro.dll -> Downloader.Small.bxh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP334\A0169876.dll -> Downloader.Small.byd : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\5.dlb -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016784.EXE -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166449.exe -> Downloader.Small.cwj : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016977.EXE -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166485.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\testtestt.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016983.EXE -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166491.exe -> Downloader.Small.dht : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016143.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016151.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016152.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016965.EXE -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166478.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167836.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dxvwhmts.exe -> Downloader.Small.dlw : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\6.dlb -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\7.dlb -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016778.EXE -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016781.EXE -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166447.exe -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166448.exe -> Downloader.Small.dnk : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016968.EXE -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166480.exe -> Downloader.Tiny.ap : Cleaned with backup (quarantined).
C:\WINDOWS\exact.exe -> Dropper.Small.aox : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\82.tmp -> Hijacker.Costrat.l : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temporary Internet Files\Content.IE5\456JKLYZ\winmad2[1].exe -> Hijacker.Costrat.l : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016959.EXE -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3164941679-1693736371-1378865824-1006\Dc55.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166472.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\stonedrv.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\art7063.tmp -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016971.EXE -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166481.exe -> Proxy.Xorpix.al : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\artAD9.tmp -> Proxy.Xorpix.al : Error during cleaning.
C:\Documents and Settings\Ike\Cookies\ike@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@www.epilot[2].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@c.goclick[2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\ike@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ike\Cookies\ike@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\NPROTECT\00017399.dll -> Trojan.Agent.fc : Cleaned with backup (quarantined).
C:\WINDOWS\jaaste.dll -> Trojan.Agent.fc : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\ughgcfwa.exe -> Trojan.Agent.pk : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temporary Internet Files\Content.IE5\456JKLYZ\2236[1].exe -> Trojan.Agent.pk : Cleaned with backup (quarantined).
C:\WINDOWS\assest.dll -> Trojan.Dialer.bi : Cleaned with backup (quarantined).
C:\WINDOWS\sasent.dll -> Trojan.Dialer.bi : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00017060.EXE -> Trojan.Dialer.pw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166536.exe -> Trojan.Dialer.pw : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00017036.EXE -> Trojan.Killav.db : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166525.exe -> Trojan.Killav.db : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\msn.exe -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.dll -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP328\A0167824.EXE -> Trojan.Sinowal.aq : Cleaned with backup (quarantined).
C:\Documents and Settings\Ike\Local Settings\Temp\2.dlb -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016787.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016974.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016980.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016986.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016989.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00016992.EXE -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166450.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166483.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166488.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166496.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166498.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP325\A0166502.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
//---- end ewido