Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 23

Thread: Help! Having problems misc virus/malware

  1. #11
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    Followed your instructions in the last post. The ComboFix log is below and the HJT logs will be in the next post.

    GW

    ComboFix 07-10-16.1 - Greg 2007-10-17 21:00:15.3 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1145 [GMT -5:00]
    Running from: C:\Documents and Settings\Greg\Desktop\ComboFix.exe

    ((((((((((((((((((((((((( Files Created from 2007-09-18 to 2007-10-18 )))))))))))))))))))))))))))))))
    .

    2007-10-16 20:24 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-10-14 12:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2007-10-13 09:03 <DIR> d-------- C:\Program Files\Trend Micro
    2007-10-13 08:33 <DIR> d-------- C:\Program Files\Common Files\Java
    2007-10-12 19:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-10-08 21:06 <DIR> d-------- C:\Program Files\Windows Defender
    2007-10-08 20:40 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\Grisoft
    2007-10-08 20:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2007-10-08 20:39 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-10-03 22:03 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
    2007-09-29 15:33 1,521,464 --a------ C:\WINDOWS\WRSetup.dll
    2007-09-29 15:33 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB8.sys
    2007-09-29 15:18 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
    2007-09-29 15:18 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
    2007-09-29 15:18 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
    2007-09-29 15:18 163,128 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
    2007-09-29 15:18 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
    2007-09-29 15:18 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
    2007-09-29 15:17 <DIR> d-------- C:\Program Files\Webroot
    2007-09-29 15:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
    2007-09-29 15:16 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\Webroot

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-16 23:53 --------- d-----w C:\Program Files\PeerGuardian2
    2007-10-13 13:35 --------- d-----w C:\Program Files\Java
    2007-10-12 23:47 --------- d-----w C:\Documents and Settings\Greg\Application Data\uTorrent
    2007-10-10 01:24 --------- d-----w C:\Documents and Settings\Greg\Application Data\AdobeUM
    2007-10-01 03:54 --------- d-----w C:\Program Files\LexmarkX83
    2007-09-29 20:32 164 ----a-w C:\install.dat
    2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
    2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
    2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
    2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
    2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
    2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
    2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
    2007-08-31 04:56 --------- d-----w C:\Program Files\GrabIt
    2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    2007-08-01 03:06 57,344 ----a-w C:\Documents and Settings\Greg\iSetupNI.dll
    2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
    2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
    2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2007-07-31 00:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
    2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
    2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
    2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
    2001-06-20 22:19 40,960 ----a-w C:\Program Files\ACMonitor_X83.exe
    .

    ((((((((((((((((((((((((((((( snapshot@2007-10-16_21.22.57.99 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2007-10-18 01:54:05 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_4c0.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 02:56]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
    "Lexmark X83 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 10:25]
    "Lexmark X83 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 12:42]
    "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-07-19 22:54]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoViewOnDrive"=0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=NVDESK32.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
    backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin PCMCIA WLAN Monitor.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin PCMCIA WLAN Monitor.lnk
    backup=C:\WINDOWS\pss\Belkin PCMCIA WLAN Monitor.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
    backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
    backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniEYE-MiniREAD Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MiniEYE-MiniREAD Launch.lnk
    backup=C:\WINDOWS\pss\MiniEYE-MiniREAD Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton GoBack.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton GoBack.lnk
    backup=C:\WINDOWS\pss\Norton GoBack.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^Event Reminder.lnk]
    path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\Event Reminder.lnk
    backup=C:\WINDOWS\pss\Event Reminder.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
    "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
    "C:\Program Files\BroadJump\Client Foundation\CFD.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
    "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
    "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
    C:\WINDOWS\system32\dla\tfswctrl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FineReader7NewsReaderPro]
    "C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    E:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
    "C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
    C:\Program Files\Microsoft Works\WkDetect.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    "C:\Program Files\Messenger\msmsgs.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
    "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    C:\WINDOWS\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWAS7_0001_N99M3108]
    "C:\DOCUME~1\Greg\LOCALS~1\Temp\winaspsnet.exe" -nag

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton SystemWorks]
    "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    "nwiz.exe" /installquiet

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
    "C:\Program Files\PeerGuardian2\pg2.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
    C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe]
    C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
    rundll32.exe "C:\WINDOWS\system32\bvmiprrp.dll",sitypnow

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
    "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
    C:\PROGRA~1\SYMNET~1\SNDMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
    "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    "C:\Program Files\Windows Defender\MSASCui.exe" -hide

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
    "C:\Program Files\Microsoft Works\wkfud.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "WMPNetworkSvc"=3 (0x3)
    "ose"=3 (0x3)
    "Omniquad MyPrivacy"=2 (0x2)
    "MDM"=2 (0x2)
    "iPodService"=3 (0x3)
    "GBPoll"=2 (0x2)
    "Creative Service for CDROM Access"=2 (0x2)
    "WinDefend"=2 (0x2)
    "WebrootSpySweeperService"=2 (0x2)

    R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS
    R2 BCMNTIO;BCMNTIO;\??\C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys
    R2 BulkUsb;Genesys Logic USB Scanner Controller NT 5.0;C:\WINDOWS\system32\Drivers\usbscan.sys
    R2 MAPMEM;MAPMEM;\??\C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys
    R3 Ich;Ich;C:\WINDOWS\system32\DRIVERS\Ich.sys
    S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys
    S3 ousb2hub;OrangeWare USB 2.0 Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys
    S3 PCMCIABKPCMXP;Belkin 11Mbps Wireless Notebook Network Adapter;C:\WINDOWS\system32\DRIVERS\bkpcmxp.sys
    S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc2.sys

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1abcc961-e6b3-11db-9bfc-00065bbaff0e}]
    AutoRun\command - E:\wd_windows_tools\setup.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-10-17 07:09:03 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    "2007-10-15 01:00:05 C:\WINDOWS\Tasks\wrSpySweeper_LC82C3849C14342B5B70A95B5A8BF8625.job"
    .
    **************************************************************************

    catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-10-17 21:26:55
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\runtime2]

    .
    Completion time: 2007-10-17 21:29:17
    C:\ComboFix2.txt ... 2007-10-16 21:24
    .
    --- E O F ---

  2. #12
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:30:32 PM, on 10/17/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Documents and Settings\Greg\Desktop\gwjunk.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 87.237.58.28:3128
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.rr.com"); (C:\Documents and Settings\GREG\Application Data\Mozilla\Profiles\default\n61r3hpz.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\GREG\Application Data\Mozilla\Profiles\default\n61r3hpz.slt\prefs.js)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - e:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - e:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102048806690
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    --
    End of file - 6934 bytes

  3. #13
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Re-scan with kaspersky

    Post:

    - a fresh HijackThis log
    - kaspersky report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  4. #14
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    Here you go. Kaspersky Log in next post.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:50:54 PM, on 10/18/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Documents and Settings\Greg\Desktop\gwjunk.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 87.237.58.28:3128
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.rr.com"); (C:\Documents and Settings\GREG\Application Data\Mozilla\Profiles\default\n61r3hpz.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\GREG\Application Data\Mozilla\Profiles\default\n61r3hpz.slt\prefs.js)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - e:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - e:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102048806690
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

    --
    End of file - 6900 bytes

  5. #15
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    To get the Kaspersky file to fit on this post I abbreviated some items.
    Doc...Set... = Documents and Settings
    Obj. is locked = Object is locked
    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Thursday, October 18, 2007 10:50:26 PM
    Operating System: MS Windows XP Home Ed., SP 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus DB last update: 19/10/2007
    Kaspersky Anti-Virus DB records: 439214
    -------------------------------------------------------------------------------
    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true
    Scan Target - My Computer:
    A:\
    C:\
    D:\
    Scan Statistics:
    Total number of scanned objects: 52469
    Number of viruses found: 4
    Number of infected objects: 10
    Number of suspicious objects: 0
    Duration of the scan process: 01:18:50

    Infected Object Name / Virus Name / Last Action
    C:\Doc...Set...\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Obj. is locked skipped
    C:\Doc...Set...\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\Application Data\Webroot\Spy Sweeper\Logs\071018191453.ses Obj. is locked skipped
    C:\Doc...Set...\Greg\Cookies\index.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj. is locked skipped
    C:\Doc...Set...\Greg\Local Settings\History\History.IE5\index.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\Local Settings\History\History.IE5\MSHist012007101820071019\index.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Obj. is locked skipped
    C:\Doc...Set...\Greg\NTUSER.DAT Obj. is locked skipped
    C:\Doc...Set...\Greg\ntuser.dat.LOG Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS039D21BB-A963-4CE3-8448-49E957A147B3.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS060EAA77-DDBA-4C99-9ADD-AB9AB5447C17.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS070C7E14-604D-49D3-97A0-5E54324B4756.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS07DF8282-30FC-4D4B-9CDA-C3988D2B66ED.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0D30840E-AF76-4E36-AEF0-F1716069B613.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0DA58CE1-4C1D-44CD-866D-7061540BCF4A.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0F96D134-49C0-4AEA-BC7E-F942B5118CE0.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS167F737D-7AFF-41B1-BAD3-3A3B5A3E1DEA.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS196763C4-3F57-4253-A4D2-4D6449E4104D.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1D31ADB8-A704-4612-BBC0-3BF2363D46FE.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F01791E-9869-4437-BB88-C684184B7D7B.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS21677260-245E-43C7-B76F-CBC505BE5C2C.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS234EC93D-B62C-4039-9C23-9B427AFF569C.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2584FEE9-E7DF-4D8E-BC0D-609C9D717713.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2663CBC1-4C91-422B-BD5B-53E027C0D12B.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2A8A150F-F5F6-48A4-9245-48B1DDB66DF8.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS322B9B12-91AD-4A71-8246-28601A03C270.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS32C8852E-630D-4DE2-9E3A-059AFD8F1AFB.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3588EF5A-D2A8-4158-A839-4CB8ABA60E9F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3AF1B981-A04A-4D85-8D49-2DC65E399A59.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3FE1CDB2-4037-4596-8184-A596FCD18997.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS425F173E-DE66-4851-9A6F-85BB6C81E2B7.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS44432E72-C34C-42A7-9D0A-EDA565158606.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS44BF293D-CCE0-4EA6-8F23-B2DB8AD5F52F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS465431A4-9DFB-4D8A-94D6-A20C6CB99EB1.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4A012F93-E82A-4A82-81B3-8B2F6A31822E.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4C3722EA-AD8B-454A-BE39-DADFF474890F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4C54C5B6-2F4B-401C-82F1-95E646ABC55E.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4E69FE6C-89F2-425F-BF2F-E492CF948A63.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS56655EF0-9045-43C7-A067-028205271976.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5CFE6024-BCB5-447F-9B85-DE504B7FDFEA.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5D9319E2-B496-47E0-8EA5-355CEC350E43.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS62D518E0-8D64-400A-A0FB-A1A245961CC2.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS65B2876C-6E93-4136-8694-29B7772614B0.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS67F6F935-CE08-48B8-BF0D-CB20A592F1C6.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6C3C419B-E3A9-4289-8685-F7DF2DA1DF88.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6D5856B4-FD49-49CD-A924-686175A7C051.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F72B032-F19A-4CF9-A208-18FABEB1CD58.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS802B577D-9753-4496-AF18-0A6ACC08652E.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS809D0ACC-5E48-4B12-83F7-72D5B47477AD.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS83C502B8-32D5-42CA-AA3C-4F0B752DF124.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS842BAEE0-38B2-4D19-A230-54E9D865CB6A.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8C0778C5-6ECF-4536-B260-F98AB16F9EB1.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8CDC8D37-3012-4EDE-8A94-852528BAE8BA.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9114ACDF-5CEA-4D07-8B20-C4B53857F0A4.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS963203C8-36C5-42D4-AE65-0A345FCBF4C2.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS98592031-2CB6-47D1-B9BD-E1DC94BC79D0.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99B41ECF-F8EC-4228-B2BF-28DE1D392E57.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B0A98EE-53D5-4CC6-B393-1BDAC2668131.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9CEB5C2D-1BC6-446C-A50B-A77BEA4BE4BC.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9FB5252E-BF09-4DAF-88FA-8E68F25E52C6.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA74C1EE7-5256-42DD-9608-61EF1C00456F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA76A040B-263D-41F0-A0B9-510AD6EAD4BC.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSACD12213-FDC8-4238-B270-5A8C6A0B4388.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAF21D4B1-A064-45B1-BA90-BB158C2F8AF4.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB0661E4F-33AF-4D5D-9262-93407F159AE2.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB40695E5-3AE4-4CD4-9FCE-3426300ADA34.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB8676134-7692-455C-9920-C31DFAB557C1.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBC37BE24-5D5D-479F-8B56-5F971FFCEFA5.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBE35C18B-5F7B-4427-97D3-D4267B59A14F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFE1B316-84F4-43A2-B4CE-EFE8D911E597.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFF6B10B-04BD-4843-9F46-834B5F66B560.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC079CC02-02C8-4A75-AB44-E8A68DA128CF.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC3A3E971-6EF4-45DA-A65D-AF3E67E9EFA7.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC4CB747D-4C81-4DB4-A794-E214CF4C1F28.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC5718033-20F7-4693-9047-270AE40A1F12.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC6A7B5DF-4F02-4346-80C7-94CA327C13FC.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC78ABA8E-1148-47D7-A9BC-44F215884147.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCAEB8C8F-ED92-4A68-BDA1-9AE2DA0F6358.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD47AB426-A1DA-4C61-AAAE-6109E3B1F1E5.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD56EAE7D-CF62-41A9-B442-5596D464F7D5.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD5F64D58-A333-49D4-A9A4-B773F05F0FD2.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD636761C-2FDF-46BA-83F6-787ADB597D27.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDC8E5F98-B1A1-4FDA-AC48-0FA0E2539B59.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDDC5734C-48AC-4DD4-8F32-1096C609DC77.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFA6E37F-D2BD-4D51-A9FC-E493343C603E.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE31A470F-81AC-4D33-B9CA-E685E1B1C136.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE67972C6-FFEA-4763-B7B5-237EB0983141.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE89F6054-B8EE-4F8A-9415-FF0BFF1267E7.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEBFF1808-C1B8-4500-A2C5-2A958677C1F5.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEEB322C9-D65B-4002-970B-5A4971467478.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEFDBBF79-FDF4-439D-A17B-25179FD97B96.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF0D93949-E574-4B94-9702-C59BD5848D4F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF617AA68-FBC3-4A7B-996B-C11FB24C9ED9.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF71C5DDC-8548-4590-A7B0-A8D94070DF30.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFA22CCB0-C310-495E-A9FF-03B32A2EECB7.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFB44D3D9-0291-412B-B8B2-6BC041EC141F.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFE0B9D8E-72C4-4225-8167-44071D9D963D.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFEFC7C86-1BBB-4196-8723-DAD4DB90D83B.tmp Obj. is locked skipped
    C:\Doc...Set...\LocalService\Cookies\index.dat Obj. is locked skipped
    C:\Doc...Set...\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj. is locked skipped
    C:\Doc...Set...\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj. is locked skipped
    C:\Doc...Set...\LocalService\Local Settings\History\History.IE5\index.dat Obj. is locked skipped
    C:\Doc...Set...\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Obj. is locked skipped
    C:\Doc...Set...\LocalService\NTUSER.DAT Obj. is locked skipped
    C:\Doc...Set...\LocalService\ntuser.dat.LOG Obj. is locked skipped
    C:\Doc...Set...\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj. is locked skipped
    C:\Doc...Set...\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj. is locked skipped
    C:\Doc...Set...\NetworkService\NTUSER.DAT Obj. is locked skipped
    C:\Doc...Set...\NetworkService\ntuser.dat.LOG Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Obj. is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Obj. is locked skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Obj. is locked skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Obj. is locked skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Obj. is locked skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters.base Obj. is locked skipped
    C:\qoobox\Quarantine\C\WINDOWS\system32\epvmrslf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\qoobox\Quarantine\C\WINDOWS\system32\nkvlkppa.dll.vir Infected: Trojan.Win32.Pakes.sc skipped
    C:\qoobox\Quarantine\C\WINDOWS\system32\rmubcphu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\qoobox\Quarantine\C\WINDOWS\system32\ttpoehoc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.wm skipped
    C:\qoobox\Quarantine\C\WINDOWS\system32\xwjxmxcd.exe.vir Infected: Trojan.Win32.Agent.bck skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Obj. is locked skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000075.exe Infected: Trojan.Win32.Agent.bck skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000084.dll Infected: Trojan.Win32.Pakes.sc skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000085.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000086.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wm skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP4\change.log Obj. is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Obj. is locked skipped
    C:\WINDOWS\SchedLgU.Txt Obj. is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Obj. is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Obj. is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Obj. is locked skipped
    C:\WINDOWS\system32\config\Antivirus.Evt Obj. is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Obj. is locked skipped
    C:\WINDOWS\system32\config\default Obj. is locked skipped
    C:\WINDOWS\system32\config\default.LOG Obj. is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Obj. is locked skipped
    C:\WINDOWS\system32\config\SAM Obj. is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Obj. is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Obj. is locked skipped
    C:\WINDOWS\system32\config\SECURITY Obj. is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Obj. is locked skipped
    C:\WINDOWS\system32\config\software Obj. is locked skipped
    C:\WINDOWS\system32\config\software.LOG Obj. is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Obj. is locked skipped
    C:\WINDOWS\system32\config\system Obj. is locked skipped
    C:\WINDOWS\system32\config\system.LOG Obj. is locked skipped
    C:\WINDOWS\system32\h323log.txt Obj. is locked skipped
    C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Obj. is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Obj. is locked skipped
    C:\WINDOWS\Temp\Perflib_Perfdata_4b4.dat Obj. is locked skipped
    C:\WINDOWS\Temp\_avast4_\Webshlock.txt Obj. is locked skipped
    C:\WINDOWS\WindowsUpdate.log Obj. is locked skipped

    Scan process completed.

  6. #16
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Empty this folder:

    C:\qoobox\Quarantine\

    Empty Recycle Bin

    All other viruses are in system restore and inactive.

    I give you later instructions how to empty it.

    Other than that, any problems left?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #17
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    I deleted the files and I'm testing out my system this weekend.

    I have done some preliminary virus/spyware scans and found some still. I'll let you know in the next day or two how it is going.

    Thank you,

    GW

  8. #18
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Ok, let me know
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #19
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    gwjunk?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  10. #20
    Junior Member
    Join Date
    Oct 2007
    Posts
    13

    Default

    Hi Shaba,

    I've been testing out my system for the last week. It seems to be running better but it still has some lingering problems. It still has some various malware items that show up in various scans. Attached are the latest Kaspersky and Hijack logs.

    Again, I appreciate all the help you have given so far.

    Thank you,

    GW

    ---------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Sunday, October 28, 2007 11:31:43 PM
    Operating System: Microsoft Windows XP Home Ed., SP2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 29/10/2007
    Kaspersky Anti-Virus database records: 447756
    ---------------------------------
    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true
    Scan Target - My Computer:
    A:\
    C:\
    D:\
    Scan Statistics:
    Total number of scanned objects: 53375
    Number of viruses found: 4
    Number of infected objects: 9
    Number of suspicious objects: 0
    Duration of the scan process: 01:21:54

    Obj/Locked = Object is locked

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Obj/Lock skipped
    C:\ " \All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Obj/Lock skipped
    C:\ " \Greg\Application Data\Webroot\Spy Sweeper\Logs\071028112030.ses Obj/Lock skipped
    C:\ " \Greg\Cookies\index.dat Obj/Lock skipped
    C:\ " \Greg\Desktop\Misc Computer Access Proxy Folder\mirc63.exe/stream/data0001/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.63 skipped
    C:\ " \Greg\Desktop\Misc Computer Access Proxy Folder\mirc63.exe/stream/data0001/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.63 skipped
    C:\ " \Greg\Desktop\Misc Computer Access Proxy Folder\mirc63.exe/stream/data0001 Infected: not-a-virus:Client-IRC.Win32.mIRC.63 skipped
    C:\ " \Greg\Desktop\Misc Computer Access Proxy Folder\mirc63.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.63 skipped
    C:\ " \Greg\Desktop\Misc Computer Access Proxy Folder\mirc63.exe NSIS: infected - 4 skipped
    C:\ " \Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj/Lock skipped
    C:\ " \Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj/Lock skipped
    C:\ " \Greg\Local Settings\History\History.IE5\index.dat Obj/Lock skipped
    C:\ " \Greg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Obj/Lock skipped
    C:\ " \Greg\NTUSER.DAT Obj/Lock skipped
    C:\ " \Greg\ntuser.dat.LOG Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS039F94B2-7088-4EF0-A73B-7DADC185594A.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS07C62954-7417-4B52-8884-367613E7D12B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS085B4323-B63E-4BAD-A91A-CAC509D7AC8C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0BAA1680-AD59-47CB-A9D1-EE900922B3AF.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C27B22D-FC7F-478B-9EE2-816A0E0D9BE0.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0D8617DD-9629-4AB7-98E7-83B427DB97B2.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS111A7CAF-CE8A-4980-BAA3-AEE8D35173BF.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12D7B109-AA58-442C-91BD-904D364DE1E8.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS161AD031-0099-4C89-B6F0-FA8AA865ED3C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F526DC0-F8BC-400C-B473-45E13FB1CD2C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS246574AB-9102-4C19-83A0-D7AE551749A2.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25937003-3290-48F1-9240-9186CB19DD5B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS26BD6BA7-6496-4BBC-8F22-037923FCB7A5.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2C8632D8-8A2E-41E9-B77F-BA66FF8FDFA6.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2E214582-2B94-41A2-9D6C-71A048346E7A.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS34905C70-2417-41A1-AFC0-2C88C43F716F.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3511B6BB-4856-4C46-A551-A157C317A435.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS39595B8F-8208-4655-B49D-6A4D19699724.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3B666C47-4F07-493F-A925-31C5366C0615.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3E6BDF0F-14CC-45CD-A011-F95F81FB7D95.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS40263562-E922-4DBC-AB6B-E477E23275FC.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS425E542E-5CE1-4524-A259-F1AE00E3B660.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS49FB966F-67C4-46E1-B1A0-B653C61A6916.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4B2A6D54-C6E6-4417-8B94-8D8EC56796F0.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4F91B085-DF25-4767-9AF3-530EDEF9EF76.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5337F9E4-B447-46C9-B590-F4F572C34B2B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS55F076FA-F8A5-4149-997E-0315872C127E.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS56481F37-53BC-42F2-8A94-5CFD7EE64E99.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5933DCDC-9889-425E-BF14-D15C8F956842.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS599DC475-3B1F-41C0-BB74-4538B1B551CC.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS63BB3E32-CCFE-4B91-863E-82D08666CBF5.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS64488E86-3889-4962-B929-165774DE5DB7.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6515A712-07CD-4497-AFAF-93F565A7AAFE.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS66E17010-9112-4C24-B896-6AC4E201850E.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS67EB2708-57E5-4D5C-97A7-DC1453DD4AA9.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6A32E06A-5358-4288-A63D-01CF68061C00.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS70FAD79C-0286-48C3-B0F5-95DE51669AF8.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS76B31F48-B761-4507-BE65-4A18378B4A2D.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7927AEA5-2329-418D-92D8-10303891E1B6.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS79FCBED3-C461-47B4-8983-15A4762DA341.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7A34FF4E-B900-4906-9D1E-E2CA87A2876C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7EE63CAC-881A-452F-B470-D08BEDCD3A27.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS801352C0-EA35-46B8-AC67-72FDE8B1B0E1.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS82B0ECF8-63D1-4574-B71B-E55CAB5EAF6C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS84FDA447-D4C2-45F4-A2C8-5B5758BD70DA.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS85CFEC9B-CB51-44A4-BE34-4FAA58A2C58A.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS86B3C182-1103-4618-A73B-CD8DA4B4E0B1.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9033DD88-23C2-4881-9207-92749AD92742.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9145443E-8A04-4DF9-8E45-82576D0F52E6.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS938DD9EB-8EDF-4620-BEBE-BB6833B70D96.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS93C4596E-DB36-4A00-9DE1-C4F6E6C41E18.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS94AE52B6-578B-4928-8480-6AC32A58CE72.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9778B845-32FE-4F16-ADAC-A3FFEA42CF62.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS978BD075-C241-4A20-9CA4-0DDE140E0702.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D4FF134-41BF-469E-B2F7-8358DD7EA021.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9FB6AA72-3956-4397-B049-87C4100C86F1.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA9B42BB1-EC3C-40AF-8EEA-2D9AD85EB997.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAA7E2FF1-EA47-485D-86DA-F5A9EE3132DC.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC1E8A40-9351-4F45-BC6E-E2E4A887BEA0.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE38B91E-8ED3-45B4-8D7F-D4F28D617A4B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB2AE8896-8019-41B5-AFC0-03C2917EE9D1.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB51CEB8F-74C0-4D7B-BC9F-5C5BA1C69F95.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB5387A5D-2690-418F-A98D-6C71997F5A6F.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB639ED4C-6C3C-4E41-9CE7-11F45B7447EB.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC0B2AEC9-4FE8-422F-B4E4-96DB3B3F9886.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC6346C84-11E3-4490-A6F7-A3C2DEBB8FB3.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC6EC1812-F8D1-43B8-AD08-9EC4EE93007C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC7FCD7D3-FD76-476F-B434-EB22A1941694.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC84AF1A7-04CD-4045-AA2F-AC4220E27E9A.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCA49200C-DBC4-4EB6-B2B2-738942735314.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCC2BB81B-DA8C-4211-B139-DD12B999A9FC.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCF8749BD-D432-4A81-95AE-30D52A0E7DDB.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD33A345F-6B23-4373-8AE1-85F47CB0088B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD4F3FC27-777A-43B0-B750-EBB471E1F527.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD5366853-5D8B-4BBA-B628-F5E6D03D05EF.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD5389D43-59AC-4C76-AD7B-00BA3E3491D8.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD597E9CB-464D-40DC-B55E-0573EAE27D4A.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDE9C7F6F-D674-41C8-81FC-93614B41903C.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE033D389-441D-4208-A333-C0B41C297293.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0A9B4BA-FAD8-4E7E-8D49-F988CDC1A346.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEAA72A39-E600-4052-A265-E0D5A10959C2.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEEB99938-6B5C-4263-9884-F78C56E9CC11.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEF2D82D5-5E18-4636-86ED-1AEEB803F194.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF00B6899-9583-4D1C-98E8-3178AF1F7D85.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF272469C-06DA-44C1-93A5-A8FDD7B9CB6B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF459C7C6-FC80-4856-971B-C47F583D7261.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8F1357B-D114-4E34-B98D-2B9E5896A6ED.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFB27D8B2-D725-4427-BB60-A829F3DA9A0B.tmp Obj/Lock skipped
    C:\ " \LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFF72A50F-7FE1-4239-A0C0-D01163D9B604.tmp Obj/Lock skipped
    C:\ " \LocalService\Cookies\index.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj/Lock skipped
    C:\ " \LocalService\Local Settings\History\History.IE5\index.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\temp\Cookies\index.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\temp\History\History.IE5\index.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Obj/Lock skipped
    C:\ " \LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Obj/Lock skipped
    C:\ " \LocalService\NTUSER.DAT Obj/Lock skipped
    C:\ " \LocalService\ntuser.dat.LOG Obj/Lock skipped
    C:\ " \NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Obj/Lock skipped
    C:\ " \NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Obj/Lock skipped
    C:\ " \NetworkService\NTUSER.DAT Obj/Lock skipped
    C:\ " \NetworkService\ntuser.dat.LOG Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Obj/Lock skipped
    C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Obj/Lock skipped
    C:\Program Files\PeerGuardian2\history.db Obj/Lock skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Obj/Lock skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Obj/Lock skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Obj/Lock skipped
    C:\Program Files\Webroot\Spy Sweeper\Masters.base Obj/Lock skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Obj/Lock skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP14\change.log Obj/Lock skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000084.dll Infected: Trojan.Win32.Pakes.sc skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000085.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ace skipped
    C:\System Volume Information\_restore{577EE6D5-F10F-45F5-B1AC-691ECAAFF2A5}\RP3\A0000086.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wm skipped
    C:\WINDOWS\Debug\PASSWD.LOG Obj/Lock skipped
    C:\ " \SchedLgU.Txt Obj/Lock skipped
    C:\ " \SoftwareDistribution\EventCache\{F01877B8-AAE9-4DB0-8EFE-08C28873C86A}.bin Obj/Lock skipped
    C:\ " \SoftwareDistribution\ReportingEvents.log Obj/Lock skipped
    C:\ " \system32\config\Antivirus.Evt Obj/Lock skipped
    C:\ " \system32\config\AppEvent.Evt Obj/Lock skipped
    C:\ " \system32\config\default Obj/Lock skipped
    C:\ " \system32\config\default.LOG Obj/Lock skipped
    C:\ " \system32\config\Internet.evt Obj/Lock skipped
    C:\ " \system32\config\SAM Obj/Lock skipped
    C:\ " \system32\config\SAM.LOG Obj/Lock skipped
    C:\ " \system32\config\SecEvent.Evt Obj/Lock skipped
    C:\ " \system32\config\SECURITY Obj/Lock skipped
    C:\ " \system32\config\SECURITY.LOG Obj/Lock skipped
    C:\ " \system32\config\software Obj/Lock skipped
    C:\ " \system32\config\software.LOG Obj/Lock skipped
    C:\ " \system32\config\SysEvent.Evt Obj/Lock skipped
    C:\ " \system32\config\system Obj/Lock skipped
    C:\ " \system32\config\system.LOG Obj/Lock skipped
    C:\ " \system32\h323log.txt Obj/Lock skipped
    C:\ " \system32\LogFiles\WUDF\WUDFTrace.etl Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\INDEX.BTR Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\INDEX.MAP Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\MAPPING.VER Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\MAPPING1.MAP Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\MAPPING2.MAP Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\OBJECTS.DATA Obj/Lock skipped
    C:\ " \system32\wbem\Repository\FS\OBJECTS.MAP Obj/Lock skipped
    C:\ " \Temp\Perflib_Perfdata_4b0.dat Obj/Lock skipped
    C:\ " \Temp\_avast4_\Webshlock.txt Obj/Lock skipped
    C:\ " \WindowsUpdate.log Obj/Lock skipped

    Scan process completed.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •