Nefas
2008-04-17, 21:34
Applications started opening on their own, mainly Internet Explorer and LimeWire, with and several strange proccesess. I would try stoping them using the task manager but they kept popping up.
I used AdAware, Trend Micro PC-cillon 2006(expired definitions), Webroot Spysweeper (expired definitions). That found many infections and stopped the Limewire problem but i still have Internet Explorer opening up.
Used Spybot and found several more infections including "Smitfraud-C.CoreService". Was able to adress all other issues except for this one.
I apreciate any help you can give me.
Here are the logs
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, April 17, 2008 8:54:30 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/04/2008
Kaspersky Anti-Virus database records: 711959
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 77622
Number of viruses found: 13
Number of infected objects: 80
Number of suspicious objects: 0
Duration of the scan process: 02:40:09
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0BC2F294-785F-44FD-977F-3260FE702CB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0FF830BA-B5B9-47E2-8AD8-F76CEDA1FA1E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1103B9D8-6F0C-4C3B-81AA-40FEB8C0111C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS11F50BD6-F458-4743-80EA-C94091B44E08.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS12686BC5-30A9-4C45-8ECB-AC2A99DBFF3F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS12FC10DF-8E61-4FD5-BE7A-ADC16DC04998.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13067D9F-86A0-4E23-8C27-0ECF9CA9B556.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13143E99-B86C-46AE-8EB6-70CA8F774E1C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS16A7F905-BD69-4646-B505-E2D85A59E20F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1952FEB5-4BAB-4FEB-936C-949BA0527CA9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1B17BBF2-6E49-4627-9DC7-3DECCAAC9578.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1E60CF1E-4321-4F3E-8290-9CFD334A698B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS21595311-052B-4A0B-8ECA-7EFFF2E6CAC4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS242E09D8-0A2D-4CEE-8343-3DA003B76BDF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2E0047D8-B218-47C0-8528-44E8757B966C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3023C5EA-E8AF-4263-856F-91419F5A3C0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3175ED6A-2C80-4647-BA65-AC742055EAC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS325A7982-5054-489C-8B92-A380B7A4F528.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS328D2A07-4018-47A3-AEBB-EDD7E1470A22.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3299E484-2E5F-4070-9608-CBF4C5E0FB35.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS346143B6-FBC4-428A-86F8-AAB8ADB8F1D5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS35FB65BB-BA5E-422C-9629-5255EB3DFC16.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS38A1B5C4-D5FF-4C4E-BB4C-1C9899C7748A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS39042DEB-4BDF-4C9B-A502-9B96BF79AF5C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3CB30C4A-D0C3-4DFC-8C51-84FB95D23D7C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3D54C89A-A943-468F-9999-78010E4998D0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS433544B2-74E0-47D8-B9B8-ABB3DFDC84F0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS44CFFC3F-25B6-44CD-85C8-AB84F38F8D9E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B2721C1-B88D-4A25-87E7-2DCD07E5A990.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4C44BE99-ACEA-43A6-ABFD-74F973D32D78.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4C6A8361-8B02-4094-86D5-941E68C36B9B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4CB721A1-0DD2-4CDC-BF38-2BC861164BF5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D2041A3-99AC-4DFE-AD95-7322244589BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5849228C-72E2-4171-98D5-AA0AF550CC09.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C2E3A92-23C7-4F39-A53D-5EBC86E9A6E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5F4A6E92-DDB2-4D05-ACFF-455C31137C50.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS61D152AC-7C1B-4D50-B266-AF4E26A70E75.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64165611-B8B3-4171-A0F6-401D4679C7B6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64F33D3E-6274-42AB-9597-04D46BAFBE60.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS66CE580C-E523-4E23-BAE5-406D8D4E70A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6803E6FA-A1D4-4761-952E-594E75FAF08C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6B7CF265-5B19-4D4F-8049-CF8FE445EEF9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6DEB86C8-B2FA-42DC-A758-C9C37B0A6338.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6EE70C49-0ED3-4C3C-9827-1089069558B8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6FABB255-7A0D-430B-BFEC-2CB9D6F55804.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS79D86D93-0C70-49BE-8688-C1990D7A048D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E01A3D3-83BA-4475-ACB3-212BB742F005.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87AEDBD4-2471-4D18-9C25-482E521547EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS88876CB7-B0AD-4076-B296-187EE2039BE2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8AD53B3D-FA98-49A3-A593-0A85DB49C985.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8B33AE6D-F2BC-47FD-96BA-1C58A256A52F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8BC61972-7B67-4D6D-846A-04350A525B6D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C9E9BD9-470D-4D3D-9DDC-3400427004F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS92A119FC-B7FD-40F8-853D-7A921F853AC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS934CEF74-BC11-44A5-B205-0C0AFE039A66.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9545268C-1EE6-428D-8932-169DA8048063.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9702375B-3F05-4631-9C23-9A1D93EE1469.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS97D082EC-3ECA-42D7-80C4-1EC16F58C5F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9806239C-F2E6-4CC1-97B8-2F13E9FA1284.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9CBE58BB-2B5F-4D49-921A-EB34F5FA8B44.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA422E5CC-DB0F-4372-A35A-A3883B34DFBC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA6572FF5-4A40-4044-A830-FAA6335D219D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA8EF9AEE-876D-4F05-86E1-8C233FD57B5B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA9E1399C-E1FC-4B7E-88F0-07E4E6243EB3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAAB10DB8-43D7-495F-8F60-999248F141C9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAB616AC5-759E-400D-BB07-EA5BB2413A72.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5058119-28A0-456B-A850-1983F410F474.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBB20E911-62D1-40E7-A435-DF2980CFA37E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC021B0D2-C1EF-468E-BD4C-2D3D740B4E7E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC243804B-8574-4346-A88D-9F855E619AF0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC4321BBB-6CB3-4AC5-895C-A4478D744DCF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC9835D79-4464-41BC-A368-B92E55F1A430.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB00A9D9-71B5-47B7-8A29-3C6207055C6C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD021F893-1828-40BF-8846-E340AFA892EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD1332973-2BC6-4551-AE64-4348132D495D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD185E3B4-49D2-4939-8A0C-D4F7F32A9A65.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD45476E2-825A-456C-A430-06E43F93FE29.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD50ECA61-AB31-4604-9C19-BECBE326C0CF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD545B3A7-3B45-4165-B7C3-95C63B1B1F94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD5AF9048-8946-46DE-8F8A-FDD1FA24CE5A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDECDC1F0-C5F5-4683-BB44-9D01083B7A59.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE128EF9D-9516-4078-A785-5521C0597CA2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE22EC6EB-C7A0-4EAC-98E5-3D757AF32F61.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE9CC4219-3D38-4A92-ABE9-A23BA5818866.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDDC37E2-0699-47F6-80A9-96DD664A17BD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF753F11C-07A5-446E-BA28-DB0D490BA54D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF98883CA-56C8-4217-93D7-F1AA37CD19D9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF9D1C798-F428-40B0-A571-8A762297560E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD0073DC-BF2B-4FFD-A07A-23E00B41E264.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD2EA671-E86A-4F0E-90CF-5FD951D8935D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFFA4CFDB-5DC4-44FC-9B5D-94623B231635.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Nefas\Application Data\Webroot\Spy Sweeper\Logs\080416232647.ses Object is locked skipped
C:\Documents and Settings\Nefas\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\lsass.exe Infected: Backdoor.Win32.VB.czs skipped
C:\Documents and Settings\Nefas\My Documents\WindowBlinds\WindowBlinds 5.50 Enhanced release 2.2.rar/WindowBlinds 5.50 Enhanced release 2.2/windowblinds550_enh.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Nefas\My Documents\WindowBlinds\WindowBlinds 5.50 Enhanced release 2.2.rar RAR: infected - 1 skipped
C:\Documents and Settings\Nefas\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Nefas\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2B2.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2C1.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2D5.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2E5.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2F2.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2F6.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2FB.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\3B9.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp/Setup.exe Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\FBD.tmp Infected: Exploit.Win32.IMG-WMF.u skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G4 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G5 Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G6 Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0EC Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0ED Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0EE Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0ED Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0EE Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0EF Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G6 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G7 Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G8 Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FC3N.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FC3N.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FFLV.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FFLV.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FM3N.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FM3N.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9G63N.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9G63N.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9GI0N.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9GI0N.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09M Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09N Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09O Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EE Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EF Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EG Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAVCNV.0EE Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAVCNV.0EF Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCUB5N.09M Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCUB5N.09N Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0ED Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0EE Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0EF Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP533\A0157085.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP537\A0163333.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP544\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Fonts\a.zip/Setup.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\WINDOWS\Fonts\a.zip ZIP: infected - 1 skipped
C:\WINDOWS\Fonts\Setup.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{A627D52B-CA37-4B4B-B26C-00B52BF29B9C}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{2152A73C-9C25-4B2C-A849-2FF5037A130A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bharebio18\bharebio182328.exe Infected: Trojan-Downloader.Win32.VB.dsk skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\crusoee.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\pinz1\cegmgr76.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\rwwnw64d.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\scnttkdn.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.aw skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe NSIS: infected - 2 skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
====================================================================================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:51 AM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://products.webroot.com/disp0201.php?pc=64150&rc=1&ps=R&oc=62&mjv=4&mnv=5&bld=607&cd=&dcc=&drc=&mo=&sid=&lang=en&loc=USA&rsc=&kc=ppbc__oi%5E%5E%5E_bc_damkp&ac=alertexp
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4F58D4C4-0786-41C0-B887-773F9965BB19} - C:\WINDOWS\system32\jkkjkhfc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://10.32.40.11/sre/Downloads/ICSScanner.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: jkkjkhfc - C:\WINDOWS\SYSTEM32\jkkjkhfc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\Nefas\My Documents\Snaps.JPG
--
End of file - 11799 bytes
====================================================================================================================
I used AdAware, Trend Micro PC-cillon 2006(expired definitions), Webroot Spysweeper (expired definitions). That found many infections and stopped the Limewire problem but i still have Internet Explorer opening up.
Used Spybot and found several more infections including "Smitfraud-C.CoreService". Was able to adress all other issues except for this one.
I apreciate any help you can give me.
Here are the logs
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, April 17, 2008 8:54:30 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/04/2008
Kaspersky Anti-Virus database records: 711959
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 77622
Number of viruses found: 13
Number of infected objects: 80
Number of suspicious objects: 0
Duration of the scan process: 02:40:09
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0BC2F294-785F-44FD-977F-3260FE702CB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0FF830BA-B5B9-47E2-8AD8-F76CEDA1FA1E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1103B9D8-6F0C-4C3B-81AA-40FEB8C0111C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS11F50BD6-F458-4743-80EA-C94091B44E08.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS12686BC5-30A9-4C45-8ECB-AC2A99DBFF3F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS12FC10DF-8E61-4FD5-BE7A-ADC16DC04998.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13067D9F-86A0-4E23-8C27-0ECF9CA9B556.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13143E99-B86C-46AE-8EB6-70CA8F774E1C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS16A7F905-BD69-4646-B505-E2D85A59E20F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1952FEB5-4BAB-4FEB-936C-949BA0527CA9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1B17BBF2-6E49-4627-9DC7-3DECCAAC9578.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1E60CF1E-4321-4F3E-8290-9CFD334A698B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS21595311-052B-4A0B-8ECA-7EFFF2E6CAC4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS242E09D8-0A2D-4CEE-8343-3DA003B76BDF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2E0047D8-B218-47C0-8528-44E8757B966C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3023C5EA-E8AF-4263-856F-91419F5A3C0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3175ED6A-2C80-4647-BA65-AC742055EAC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS325A7982-5054-489C-8B92-A380B7A4F528.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS328D2A07-4018-47A3-AEBB-EDD7E1470A22.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3299E484-2E5F-4070-9608-CBF4C5E0FB35.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS346143B6-FBC4-428A-86F8-AAB8ADB8F1D5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS35FB65BB-BA5E-422C-9629-5255EB3DFC16.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS38A1B5C4-D5FF-4C4E-BB4C-1C9899C7748A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS39042DEB-4BDF-4C9B-A502-9B96BF79AF5C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3CB30C4A-D0C3-4DFC-8C51-84FB95D23D7C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3D54C89A-A943-468F-9999-78010E4998D0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS433544B2-74E0-47D8-B9B8-ABB3DFDC84F0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS44CFFC3F-25B6-44CD-85C8-AB84F38F8D9E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B2721C1-B88D-4A25-87E7-2DCD07E5A990.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4C44BE99-ACEA-43A6-ABFD-74F973D32D78.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4C6A8361-8B02-4094-86D5-941E68C36B9B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4CB721A1-0DD2-4CDC-BF38-2BC861164BF5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D2041A3-99AC-4DFE-AD95-7322244589BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5849228C-72E2-4171-98D5-AA0AF550CC09.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C2E3A92-23C7-4F39-A53D-5EBC86E9A6E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5F4A6E92-DDB2-4D05-ACFF-455C31137C50.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS61D152AC-7C1B-4D50-B266-AF4E26A70E75.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64165611-B8B3-4171-A0F6-401D4679C7B6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64F33D3E-6274-42AB-9597-04D46BAFBE60.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS66CE580C-E523-4E23-BAE5-406D8D4E70A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6803E6FA-A1D4-4761-952E-594E75FAF08C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6B7CF265-5B19-4D4F-8049-CF8FE445EEF9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6DEB86C8-B2FA-42DC-A758-C9C37B0A6338.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6EE70C49-0ED3-4C3C-9827-1089069558B8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6FABB255-7A0D-430B-BFEC-2CB9D6F55804.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS79D86D93-0C70-49BE-8688-C1990D7A048D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E01A3D3-83BA-4475-ACB3-212BB742F005.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87AEDBD4-2471-4D18-9C25-482E521547EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS88876CB7-B0AD-4076-B296-187EE2039BE2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8AD53B3D-FA98-49A3-A593-0A85DB49C985.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8B33AE6D-F2BC-47FD-96BA-1C58A256A52F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8BC61972-7B67-4D6D-846A-04350A525B6D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C9E9BD9-470D-4D3D-9DDC-3400427004F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS92A119FC-B7FD-40F8-853D-7A921F853AC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS934CEF74-BC11-44A5-B205-0C0AFE039A66.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9545268C-1EE6-428D-8932-169DA8048063.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9702375B-3F05-4631-9C23-9A1D93EE1469.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS97D082EC-3ECA-42D7-80C4-1EC16F58C5F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9806239C-F2E6-4CC1-97B8-2F13E9FA1284.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9CBE58BB-2B5F-4D49-921A-EB34F5FA8B44.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA422E5CC-DB0F-4372-A35A-A3883B34DFBC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA6572FF5-4A40-4044-A830-FAA6335D219D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA8EF9AEE-876D-4F05-86E1-8C233FD57B5B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA9E1399C-E1FC-4B7E-88F0-07E4E6243EB3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAAB10DB8-43D7-495F-8F60-999248F141C9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAB616AC5-759E-400D-BB07-EA5BB2413A72.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5058119-28A0-456B-A850-1983F410F474.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBB20E911-62D1-40E7-A435-DF2980CFA37E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC021B0D2-C1EF-468E-BD4C-2D3D740B4E7E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC243804B-8574-4346-A88D-9F855E619AF0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC4321BBB-6CB3-4AC5-895C-A4478D744DCF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC9835D79-4464-41BC-A368-B92E55F1A430.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB00A9D9-71B5-47B7-8A29-3C6207055C6C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD021F893-1828-40BF-8846-E340AFA892EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD1332973-2BC6-4551-AE64-4348132D495D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD185E3B4-49D2-4939-8A0C-D4F7F32A9A65.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD45476E2-825A-456C-A430-06E43F93FE29.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD50ECA61-AB31-4604-9C19-BECBE326C0CF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD545B3A7-3B45-4165-B7C3-95C63B1B1F94.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD5AF9048-8946-46DE-8F8A-FDD1FA24CE5A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDECDC1F0-C5F5-4683-BB44-9D01083B7A59.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE128EF9D-9516-4078-A785-5521C0597CA2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE22EC6EB-C7A0-4EAC-98E5-3D757AF32F61.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE9CC4219-3D38-4A92-ABE9-A23BA5818866.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDDC37E2-0699-47F6-80A9-96DD664A17BD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF753F11C-07A5-446E-BA28-DB0D490BA54D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF98883CA-56C8-4217-93D7-F1AA37CD19D9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF9D1C798-F428-40B0-A571-8A762297560E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD0073DC-BF2B-4FFD-A07A-23E00B41E264.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD2EA671-E86A-4F0E-90CF-5FD951D8935D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFFA4CFDB-5DC4-44FC-9B5D-94623B231635.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Nefas\Application Data\Webroot\Spy Sweeper\Logs\080416232647.ses Object is locked skipped
C:\Documents and Settings\Nefas\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Nefas\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Nefas\lsass.exe Infected: Backdoor.Win32.VB.czs skipped
C:\Documents and Settings\Nefas\My Documents\WindowBlinds\WindowBlinds 5.50 Enhanced release 2.2.rar/WindowBlinds 5.50 Enhanced release 2.2/windowblinds550_enh.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Nefas\My Documents\WindowBlinds\WindowBlinds 5.50 Enhanced release 2.2.rar RAR: infected - 1 skipped
C:\Documents and Settings\Nefas\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Nefas\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2B2.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2C1.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2D5.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2E5.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2F2.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2F6.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2FB.tmp Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\3B9.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp/Setup.exe Infected: Virus.Win32.Fontra.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\BE.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\FBD.tmp Infected: Exploit.Win32.IMG-WMF.u skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G4 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G5 Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9C0LV.0G6 Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DQQV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0EC Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0ED Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9DSLV.0EE Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ENLV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0ED Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0EE Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9ETLV.0EF Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G6 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G7 Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9EVQV.0G8 Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FC3N.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FC3N.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FFLV.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FFLV.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FM3N.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9FM3N.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9G63N.09L Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9G63N.09M Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9GI0N.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9GI0N.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09M Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09N Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HDQV.09O Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSS9HSLV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EE Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EF Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAV5NV.0EG Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAVCNV.0EE Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSAVCNV.0EF Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCUB5N.09M Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCUB5N.09N Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSCVDEF.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSDVCVF.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0ED Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0EE Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSFVTLV.0EF Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09J Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09K Infected: not-a-virus:PSWTool.Win32.MailPassView.130 skipped
C:\Program Files\Trend Micro\Internet Security 2006\VSSGUVVV.09L Infected: not-a-virus:PSWTool.Win32.Outlooker skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP533\A0157085.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP537\A0163333.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\System Volume Information\_restore{4DF7BEB3-E3D2-473C-B32D-682F2CA7D884}\RP544\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Fonts\a.zip/Setup.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\WINDOWS\Fonts\a.zip ZIP: infected - 1 skipped
C:\WINDOWS\Fonts\Setup.exe Infected: Trojan-Downloader.Win32.VB.dck skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{A627D52B-CA37-4B4B-B26C-00B52BF29B9C}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{2152A73C-9C25-4B2C-A849-2FF5037A130A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bharebio18\bharebio182328.exe Infected: Trojan-Downloader.Win32.VB.dsk skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\crusoee.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\pinz1\cegmgr76.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\rwwnw64d.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\scnttkdn.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.aw skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe NSIS: infected - 2 skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
====================================================================================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:51 AM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://products.webroot.com/disp0201.php?pc=64150&rc=1&ps=R&oc=62&mjv=4&mnv=5&bld=607&cd=&dcc=&drc=&mo=&sid=&lang=en&loc=USA&rsc=&kc=ppbc__oi%5E%5E%5E_bc_damkp&ac=alertexp
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4F58D4C4-0786-41C0-B887-773F9965BB19} - C:\WINDOWS\system32\jkkjkhfc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://10.32.40.11/sre/Downloads/ICSScanner.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: jkkjkhfc - C:\WINDOWS\SYSTEM32\jkkjkhfc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\Nefas\My Documents\Snaps.JPG
--
End of file - 11799 bytes
====================================================================================================================