OK, I followed your procedure. HJT and Panda report logs follow below.
First though, a few notes:
1. I decided to keep Weatherbug
2. I did NOT find C:\WINDOWS\System32\wer8274.dll but instead found wer8274.ini and wer8274.tmp. I did NOT delete these.
3. I did NOT find C:\wp.exe but instead found wp.bmp. I did NOT delete this file.
4. Panda would NOT run with my FireFox browser, so I ran it from IE 6.x PandaScan found lots of stuff. How much of it is serious?
Thanks in advance for taking a look at these.
Here's my HJT log AFTER I made your changes:
Logfile of HijackThis v1.99.1
Scan saved at 5:20:08 PM, on 1/25/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HDD Health\HDDHealth.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Utilities\Security\HiJackThis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "file:///C:/DWeaverSites/DE%20Netscape%20Home%20Page/DEWWWPortalDW.htm"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\HDDHealth.exe -wl
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE" -aim
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1162854852734O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Here's the Panda Scan AFTER I made your changes:
Incident Status Location
Hacktool:Exploit/URLSpoof Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0000531.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0002251.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0002316.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0002346.~]
Virus:Trj/Goldun.IP Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[setup.zip][Setup.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0002647.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003055.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003291.~]
Hacktool:Exploit/URLSpoof Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003319.~]
Virus:Trj/Goldun.Q Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[setup.rar][SecurityEgold.EXE]
Virus:Trj/Mitglieder.BO Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[345556.rar][dddd.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003383.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003538.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0003591.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0004625.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0004686.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0005006.~]
Virus:W32/Sober.U.worm!CME-414 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[your_text.zip][mail.document.Datex-packed.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0005206.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0005613.~]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[account_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[our_secret.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[our_secret.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0006782.~]
Virus:W32/Bagle.ER.worm Disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[new__price.zip][06.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0009842.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0013063.~]
Hacktool:Exploit/iFrame Not disinfected C:\Data\BackUp Stuff\Netscape\Mail\mail.earthlink.net\Inbox[~0016416.~]
Adware:adware/cws Not disinfected C:\Documents and Settings\All Users\Favorites\Download Free Spyware Remover.url
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Dennis\.jpi_cache\file\1.0\Dummy.class-5db50b5e-48120a14.class
Virus:Trj/Java.Binny.A Disinfected C:\Documents and Settings\Dennis\.jpi_cache\jar\1.0\archive.jar-60d4ac05-5e04d544.zip[Mein.class]
Virus:Trj/Java.Binny.A Disinfected C:\Documents and Settings\Dennis\.jpi_cache\jar\1.0\archive.jar-60d4ac05-5e04d544.zip[Beyond.class]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.com.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[counter.hitslink.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.adtech.de/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[hc2.humanclick.com/hc/74139060]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Firefox\Profiles\5rhvumn1.default\cookies.txt[.target.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.atwola.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.questionmarket.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.target.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.target.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.overture.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.advertising.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.adtech.de/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.fastclick.net/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[counter.hitslink.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.hitbox.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[hc2.humanclick.com/hc/74139060]
Hacktool:Exploit/URLSpoof Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0000531.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0002251.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0002316.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0002346.~]
Virus:Trj/Goldun.IP Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[setup.zip][Setup.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0002647.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003055.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003291.~]
Hacktool:Exploit/URLSpoof Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003319.~]
Virus:Trj/Goldun.Q Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[setup.rar][SecurityEgold.EXE]
Virus:Trj/Mitglieder.BO Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[345556.rar][dddd.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003383.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003538.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0003591.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0004625.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0004686.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0005006.~]
Virus:W32/Sober.U.worm!CME-414 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[your_text.zip][mail.document.Datex-packed.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0005206.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0005613.~]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[account_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[our_secret.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[error-mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[our_secret.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[account_info-text.zip][Winzipped-Text_Data.txt .pif]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0006782.~]
Virus:W32/Bagle.ER.worm Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[new__price.zip][06.exe]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0009842.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0013063.~]
Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[~0016416.~]
Virus:Trj/Haxdoor.LZ Disinfected C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\Mail\mail.earthlink.net\Inbox[WC2905036.zip][WC2905036.exe]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@ad.yieldmanager[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@belnk[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@burstnet[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@dist.belnk[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@www.burstbeacon[2].txt
Adware:Adware/Tubby Not disinfected C:\WINDOWS\system32\MTC.ini
Adware:Adware/TopSpyware Not disinfected C:\WINDOWS\system32\spoolsrv32.exe
Adware:adware/bluescreenwarning Not disinfected C:\wp.bmp
Spyware:Cookie/Atlas DMT Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.atdmt.com/]
Spyware:Cookie/Statcounter Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.statcounter.com/]
Spyware:Cookie/Maxserving Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.maxserving.com/]
Spyware:Cookie/FastClick Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.fastclick.net/]
Spyware:Cookie/Hitbox Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.hitbox.com/]
Spyware:Cookie/Casalemedia Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Advertising Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.advertising.com/]
Spyware:Cookie/2o7 Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Com.com Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.com.com/]
Spyware:Cookie/Bluestreak Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.bluestreak.com/]
Spyware:Cookie/2o7 Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Serving-sys Not disinfected D:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\0d3iakhl.slt\cookies.txt[.serving-sys.com