hi i need help with virtumonde :sad:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 2:37:03 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/06/2008
Kaspersky Anti-Virus database records: 826461
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 118166
Number of viruses found: 33
Number of infected objects: 70
Number of suspicious objects: 0
Duration of the scan process: 01:53:55
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\sentinel\2.1\gwhashs.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\cert8.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\history.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\key3.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\search.sqlite Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\gido\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\MSHist012008060420080605\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\90PD1818\installer_gr[1].exe Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\gido\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\CLONECDv5.2.9.1\Slysoft.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar RAR: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe NSIS: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\MshConf\scoffset.bin.incr Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0022160.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sca skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023165.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trw skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP101\A0024183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.srh skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP102\A0024329.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP103\A0024522.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.syt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP105\A0024798.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0025939.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tra skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sce skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026146.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026314.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0026483.dll Infected: Trojan.Win32.Monder.jn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0027519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028599.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028612.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028618.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028783.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028784.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP112\A0029206.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP113\A0029276.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP114\A0029445.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP115\change.log Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010746.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010747.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP64\A0011071.dll Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP70\A0015913.exe Infected: Trojan.Win32.Obfuscated.aqn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018079.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021752.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqy skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP98\A0022049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022109.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sbz skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022137.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sby skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S3EED914A.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\arqpwvyp.dll Object is locked skipped
C:\WINDOWS\system32\axutogcf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\deytfypy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\gktgiajq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqz skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\lwoggatw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tro skipped
C:\WINDOWS\system32\sssnuvkw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn skipped
C:\WINDOWS\system32\svdhost.exe Infected: Net-Worm.Win32.Kolab.ws skipped
C:\WINDOWS\system32\tthxekms.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wvokwjas.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:53:19 μμ, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rmctrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE
C:\WINDOWS\system32\svdhost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe"
O4 - HKLM\..\Run: [Windows Sound] svdhost.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [b41cca23] rundll32.exe "C:\WINDOWS\system32\pwfiidao.dll",b
O4 - HKLM\..\Run: [BMb72ff9bf] Rundll32.exe "C:\WINDOWS\system32\icpdgcoe.dll",s
O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [bifmi] c:\documents and settings\gido\local settings\application data\bifmi.exe bifmi
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Θύρα Symantec Fax Starter Edition.lnk = C:\Program Files\Microsoft Office\Office\1032\OLFSNT40.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Mahjong Escape - Ancient Japan\Images\stg_drm.ocx
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mahjong Escape - Ancient Japan\Images\armhelper.ocx
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
--
End of file - 8882 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 2:37:03 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/06/2008
Kaspersky Anti-Virus database records: 826461
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 118166
Number of viruses found: 33
Number of infected objects: 70
Number of suspicious objects: 0
Duration of the scan process: 01:53:55
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\sentinel\2.1\gwhashs.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\cert8.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\history.dat Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\key3.db Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\search.sqlite Object is locked skipped
C:\Documents and Settings\gido\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\gido\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Application Data\Mozilla\Firefox\Profiles\r3s0fnmq.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\History\History.IE5\MSHist012008060420080605\index.dat Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\90PD1818\installer_gr[1].exe Object is locked skipped
C:\Documents and Settings\gido\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\gido\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\gido\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\CLONECDv5.2.9.1\Slysoft.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Rsrc-Package: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Rsrc-Package: infected - 2 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab/UNINST~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar/RapidShare_Download_Direct pro + crack/setup/dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar RAR: infected - 3 skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\Documents and Settings\gido\Τα έγγραφά μου\Ληφθέντα αρχεία\Internet TV\TVUPlayer2.3.3beta2.exe NSIS: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\MshConf\scoffset.bin.incr Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES Object is locked skipped
C:\Program Files\Panda Security\Panda Internet Security 2008\f4d4851e8935eebef0f2eb52b3212bc9PSK_NAMES2 Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0022160.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sca skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023165.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023188.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rsp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP100\A0023189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trw skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP101\A0024183.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.srh skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP102\A0024329.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP103\A0024522.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.syt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP105\A0024798.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0025939.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tra skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sce skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026146.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trp skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP107\A0026314.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0026483.dll Infected: Trojan.Win32.Monder.jn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP109\A0027519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028599.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028612.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028618.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028783.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP110\A0028784.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP112\A0029206.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP113\A0029276.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vps skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP114\A0029445.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP115\change.log Object is locked skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010746.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP60\A0010747.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.ec skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP61\A0010792.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP64\A0011071.dll Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP70\A0015913.exe Infected: Trojan.Win32.Obfuscated.aqn skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe/data0017 Infected: Trojan.Win32.Agent.qwt skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP71\A0017207.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018079.exe Infected: Backdoor.Win32.Hupigon.cdnk skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab/NERO9U~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP80\A0018081.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021752.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqy skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP97\A0021777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP98\A0022049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trg skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022109.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sbz skipped
C:\System Volume Information\_restore{70720771-0E60-443A-AAFA-4AF9A4DFD64D}\RP99\A0022137.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sby skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S3EED914A.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\arqpwvyp.dll Object is locked skipped
C:\WINDOWS\system32\axutogcf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\deytfypy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpu skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\gktgiajq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rqz skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\lwoggatw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tro skipped
C:\WINDOWS\system32\sssnuvkw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn skipped
C:\WINDOWS\system32\svdhost.exe Infected: Net-Worm.Win32.Kolab.ws skipped
C:\WINDOWS\system32\tthxekms.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wvokwjas.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wpv skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:53:19 μμ, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rmctrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE
C:\WINDOWS\system32\svdhost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2008\Inicio.exe"
O4 - HKLM\..\Run: [Windows Sound] svdhost.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [b41cca23] rundll32.exe "C:\WINDOWS\system32\pwfiidao.dll",b
O4 - HKLM\..\Run: [BMb72ff9bf] Rundll32.exe "C:\WINDOWS\system32\icpdgcoe.dll",s
O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [bifmi] c:\documents and settings\gido\local settings\application data\bifmi.exe bifmi
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Θύρα Symantec Fax Starter Edition.lnk = C:\Program Files\Microsoft Office\Office\1032\OLFSNT40.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Mahjong Escape - Ancient Japan\Images\stg_drm.ocx
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mahjong Escape - Ancient Japan\Images\armhelper.ocx
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda internet security 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\PsImSvc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
--
End of file - 8882 bytes