Heres the Ewido log, it simply keeps coming back, files get created in the Windows/Temp folder even in safe mode. My guess is Ewido does remove the trojans but something keeps re-installing them. It happened after I opened an .exe (which I don't have anymore). My guess is that .exe installed something that keeps installing these files in the Temp folder. Is there anyway I can find out what's creating them?
Quote:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 22:04:13 8-9-2006
+ Scan result:
C:\Documents and Settings\XA4\Local Settings\Temporary Internet Files\Content.IE5\GF4JQFY5\srvoxg[1].exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
C:\Documents and Settings\XA4\Local Settings\Temporary Internet Files\Content.IE5\GF4JQFY5\srvpzh[1].exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
C:\Documents and Settings\XA4\Local Settings\Temporary Internet Files\Content.IE5\O327M389\srvtjk[1].exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win14C.tmp.exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win7.tmp.exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\winA.tmp.exe -> Dialer.PlayGames.l : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\XA4\Application Data\Mozilla\Firefox\Profiles\hjnp1ovv.default\coo kies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\XA4\Local Settings\Temporary Internet Files\Content.IE5\O327M389\srvzak[1].exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\winB.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
::Report end
|