PDA

View Full Version : How to Remove W32 Autorun ? (HJT and Kaspersky logs)



meteor69
2007-09-21, 16:28
hi, i am using avast and it cannot repair the w32 autorun virus. i also scanned my pc with spybot and it was able to successfully remove the malware/spyware it detected. i hope you could help me thank you! :)

Below are the HJT file and the Kaspersky log files:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:39 PM, on 9/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Windows Defender\MsMpEng.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccProxy.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\Program Files\Norton Internet Security\ISSVC.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
F:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
F:\Program Files\Ahead\InCD\InCD.exe
F:\Program Files\Windows Defender\MSASCui.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\system32\svbhost.exe
F:\Program Files\QuickFix\QuickFix.exe
F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\uTorrent\uTorrent.exe
F:\Program Files\Last.fm\LastFMHelper.exe
F:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\NOTEPAD.EXE
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.finderg.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - F:\Program Files\FlashGet\jccatch.dll
O2 - BHO: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - F:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - F:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NXIECatcher Class - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - F:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - F:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: GigaSize toolbar - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - F:\Program Files\GigaSize.com Inc\GigaSize Toolbar\Kenciatb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - F:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - F:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - F:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - F:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - F:\Program Files\Xi\NetXfer\NXToolBar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - F:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: GigaSize toolbar - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - F:\Program Files\GigaSize.com Inc\GigaSize Toolbar\Kenciatb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
O4 - HKLM\..\Run: [InCD] "F:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [Windows Defender] "F:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Video Driver] svbhost.exe
O4 - HKLM\..\Run: [RavAV] F:\WINDOWS\RavMonE.exe
O4 - HKLM\..\Run: [QuickFix] "F:\Program Files\QuickFix\QuickFix.exe"
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Video Driver] svbhost.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "F:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Hitman Pro SurfRight Helper] "F:\Program Files\Hitman Pro\srhelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] F:\Program Files\eMule\emule.exe -AutoStart
O4 - HKCU\..\Run: [uTorrent] "F:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: AutorunsDisabled
O4 - Startup: Yahoo! Widget Engine.lnk = F:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: Last.fm Helper.lnk = F:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Service Manager.lnk = F:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - F:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with &DAP - F:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Download with FlashGet - F:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Yahoo! Search - file:///F:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download &all with DAP - F:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download all by NetXfer - F:\Program Files\Xi\NetXfer\NXAddList.html
O8 - Extra context menu item: Download by NetXfer - F:\Program Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///F:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///F:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {0015690D-1D8A-45bc-81A7-B7C63E9CABCD} - F:\Program Files\GigaSize.com Inc\GigaSize Toolbar\Kenciatb.dll
O9 - Extra 'Tools' menuitem: GigaSize toolbar - {0015690D-1D8A-45bc-81A7-B7C63E9CABCD} - F:\Program Files\GigaSize.com Inc\GigaSize Toolbar\Kenciatb.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/chuzzle/popcaploader_v6.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/rssoft.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - F:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - F:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - F:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - F:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - F:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - F:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - F:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 14213 bytes

meteor69
2007-09-21, 16:28
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, September 21, 2007 9:16:51 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 21/09/2007
Kaspersky Anti-Virus database records: 421572
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 87240
Number of viruses found: 17
Number of infected objects: 74
Number of suspicious objects: 0
Duration of the scan process: 02:05:48

Infected Object Name / Virus Name / Last Action
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-02032007-044918.log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\cert8.db Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\flashgot.log Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\history.dat Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\key3.db Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\parent.lock Object is locked skipped
F:\Documents and Settings\base home\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\urlclassifier2.sqlite Object is locked skipped
F:\Documents and Settings\base home\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Last.fm\Client\lastfmhelper.log Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7C814DE0-559A-4483-B292-ABBDC405504B} Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\Cache\_CACHE_001_ Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\Cache\_CACHE_002_ Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\Cache\_CACHE_003_ Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Application Data\Mozilla\Firefox\Profiles\ww7noxh4.Default User\Cache\_CACHE_MAP_ Object is locked skipped
F:\Documents and Settings\base home\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Temp\Del162.tmp Infected: Virus.Win32.AutoRun.k skipped
F:\Documents and Settings\base home\Local Settings\Temp\Del41.tmp Infected: Virus.Win32.AutoRun.k skipped
F:\Documents and Settings\base home\Local Settings\Temp\Perflib_Perfdata_e84.dat Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Temp\~DFBCA6.tmp Object is locked skipped
F:\Documents and Settings\base home\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\base home\My Documents\Downloads\KVCD - Where are my Children (1994).tawoz\Where.are.my.Children.KVCD.by.tawoz.bin Object is locked skipped
F:\Documents and Settings\base home\ntuser.dat Object is locked skipped
F:\Documents and Settings\base home\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\base home\svshost.exe Infected: Backdoor.Win32.Agobot.ala skipped
F:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
F:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
F:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\master.mdf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\mastlog.ldf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\model.mdf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\modellog.ldf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\tempdb.mdf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Data\templog.ldf Object is locked skipped
F:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\LOG\ERRORLOG Object is locked skipped
F:\Program Files\Norton AntiVirus\Quarantine\004F5F96 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\0377056C Infected: Trojan-Downloader.Win32.Small.awa skipped
F:\Program Files\Norton AntiVirus\Quarantine\1053185C Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\108268A7 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\109F76AC Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\12360912 Infected: Trojan-Downloader.Win32.Agent.qx skipped
F:\Program Files\Norton AntiVirus\Quarantine\12FD2C37.exe Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\136C3FBC.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped
F:\Program Files\Norton AntiVirus\Quarantine\138365A3.dll Infected: Trojan-PSW.Win32.LdPinch.os skipped
F:\Program Files\Norton AntiVirus\Quarantine\13860FA0.exe Infected: Trojan-Downloader.Win32.Agent.bbh skipped
F:\Program Files\Norton AntiVirus\Quarantine\138A399C.exe Infected: Backdoor.Win32.Agent.iw skipped
F:\Program Files\Norton AntiVirus\Quarantine\13900D95.exe Infected: not-virus:Hoax.Win32.Renos.f skipped
F:\Program Files\Norton AntiVirus\Quarantine\149E7CC6 Infected: Trojan-Downloader.Win32.Small.atl skipped
F:\Program Files\Norton AntiVirus\Quarantine\14E7461C.DLL Infected: Backdoor.Win32.Agent.iw skipped
F:\Program Files\Norton AntiVirus\Quarantine\160634DF.exe Infected: Trojan-Downloader.Win32.Agent.bbh skipped
F:\Program Files\Norton AntiVirus\Quarantine\19182991 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\1C2F32AB Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\1CAB5D38 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\225345CA Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\237C3C10 Infected: Trojan-Downloader.Win32.Agent.qx skipped
F:\Program Files\Norton AntiVirus\Quarantine\237F660C Infected: not-virus:Hoax.Win32.Renos.f skipped
F:\Program Files\Norton AntiVirus\Quarantine\23FE4B80 Infected: Trojan-Downloader.Win32.Agent.ho skipped
F:\Program Files\Norton AntiVirus\Quarantine\24051F79 Infected: Trojan-PSW.Win32.LdPinch.os skipped
F:\Program Files\Norton AntiVirus\Quarantine\240B7372/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
F:\Program Files\Norton AntiVirus\Quarantine\240B7372/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
F:\Program Files\Norton AntiVirus\Quarantine\240B7372/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
F:\Program Files\Norton AntiVirus\Quarantine\240B7372 ZIP: infected - 3 skipped
F:\Program Files\Norton AntiVirus\Quarantine\240B7372 CryptFF: infected - 3 skipped
F:\Program Files\Norton AntiVirus\Quarantine\241F6F5C Infected: Trojan-Downloader.Win32.Ani.c skipped
F:\Program Files\Norton AntiVirus\Quarantine\262F43A2 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\270E2822 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\2711521E Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\27147C1B Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\29C24841.exe Infected: Trojan-Downloader.Win32.Agent.bbh skipped
F:\Program Files\Norton AntiVirus\Quarantine\2D173B7E Infected: Backdoor.Win32.Agent.iw skipped
F:\Program Files\Norton AntiVirus\Quarantine\2D3A0956 Infected: Trojan-PSW.Win32.PdPinch.gen skipped
F:\Program Files\Norton AntiVirus\Quarantine\2EAB11C0 Infected: Trojan-Downloader.Win32.Agent.ho skipped
F:\Program Files\Norton AntiVirus\Quarantine\2EAF3BBD Infected: Trojan-Downloader.Win32.Agent.qx skipped
F:\Program Files\Norton AntiVirus\Quarantine\2FD57E79 Infected: Trojan.Win32.Dialer.ht skipped
F:\Program Files\Norton AntiVirus\Quarantine\2FD82876 Infected: Trojan.Win32.Dialer.ht skipped
F:\Program Files\Norton AntiVirus\Quarantine\308C637D Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\35CA7A66 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\365E7A3A Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\37FB52FC Infected: Backdoor.Win32.Agent.iw skipped
F:\Program Files\Norton AntiVirus\Quarantine\39B9393F Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\3D0A7780 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\41E937E7 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\4C6D2B13 Infected: Trojan-Clicker.Win32.Tiny.c skipped
F:\Program Files\Norton AntiVirus\Quarantine\4E7A52F9 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\566754AC Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\58994195 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\5A3B284A Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\66B930CB Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\6DBC2DBB Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\73AF7520 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\73CE798D Infected: Backdoor.Win32.Agent.iw skipped
F:\Program Files\Norton AntiVirus\Quarantine\743015A5 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\760735A4 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\79E13D4E Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\7A634E57 Infected: Trojan-Downloader.Win32.Small.bcd skipped
F:\Program Files\Norton AntiVirus\Quarantine\7F782368 Infected: Trojan-PSW.Win32.LdPinch.os skipped
F:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
F:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
F:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
F:\System Volume Information\_restore{CAF55612-3FA8-42ED-8CF9-ECBF760FB464}\RP1\A0001384.dll Infected: Virus.Win32.AutoRun.k skipped
F:\System Volume Information\_restore{CAF55612-3FA8-42ED-8CF9-ECBF760FB464}\RP1\A0001385.dll Infected: Virus.Win32.AutoRun.k skipped
F:\System Volume Information\_restore{CAF55612-3FA8-42ED-8CF9-ECBF760FB464}\RP1\change.log Object is locked skipped
F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
F:\WINDOWS\SchedLgU.Txt Object is locked skipped
F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
F:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
F:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
F:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
F:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\default Object is locked skipped
F:\WINDOWS\system32\config\default.LOG Object is locked skipped
F:\WINDOWS\system32\config\Internet.evt Object is locked skipped
F:\WINDOWS\system32\config\SAM Object is locked skipped
F:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
F:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\SECURITY Object is locked skipped
F:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
F:\WINDOWS\system32\config\software Object is locked skipped
F:\WINDOWS\system32\config\software.LOG Object is locked skipped
F:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\system Object is locked skipped
F:\WINDOWS\system32\config\system.LOG Object is locked skipped
F:\WINDOWS\system32\config\WindowsPowerShell.evt Object is locked skipped
F:\WINDOWS\system32\crss.exebak Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\dnscon70.dll Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\h323log.txt Object is locked skipped
F:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
F:\WINDOWS\system32\mstcpcon20.dll Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\SR1000R.DLL Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\trz15.tmp Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\trz16.tmp Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
F:\WINDOWS\Temp\Perflib_Perfdata_368.dat Object is locked skipped
F:\WINDOWS\Temp\Perflib_Perfdata_820.dat Object is locked skipped
F:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
F:\WINDOWS\Temp\_ISTMPI.DIR\autorun.inf Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\Temp\_ISTMPI.DIR\mmc32.exe Infected: Virus.Win32.AutoRun.k skipped
F:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.