Rawkus
2008-04-19, 23:16
I have been unable to remove Smitfraud.Core.Cache from my system. I have also been receiving random popups and even a popup claiming to be for Spybot ( http://official-2008.com/spybot/ ) Here are my logs from the Kaspersky Scan and HijackThis. Thank you for your time and assistance.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 19, 2008 11:29:58 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/04/2008
Kaspersky Anti-Virus database records: 715483
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 69559
Number of viruses found: 36
Number of infected objects: 140
Number of suspicious objects: 0
Duration of the scan process: 01:03:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\Bree\Application Data\BFGTOOLBAR\bfgtoolbarDLL.zip/bfgtoolbar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.u skipped
C:\Documents and Settings\Bree\Application Data\BFGTOOLBAR\bfgtoolbarDLL.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\cert8.db Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\history.dat Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\key3.db Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\parent.lock Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Bree\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064900.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064901.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064902.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064903.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064912.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064914.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064915.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064917.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064918.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064919.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064920.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064921.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064923.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064924.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064926.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064927.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064929.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064931.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064932.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064934.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064935.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064936.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064937.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065037.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065833.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065834.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065835.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\ApplicationHistory\TransferAgent.exe.91f03f4d.ini.inuse Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\BVRP Software\NetWaiting\MoHlog.txt Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_219.wmdb Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\History\History.IE5\MSHist012008041920080420\index.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temp\Perflib_Perfdata_dc8.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temp\snapsnet.exe/data0006 Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Documents and Settings\Bree\Local Settings\Temp\snapsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Bree\Local Settings\Temp\~DF9796.tmp Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip ZIP: infected - 4 skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\snapsnet[1].exe/data0006 Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bree\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bree\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\forms.fdb Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\static Object is locked skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\11.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\14.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\171.tmp Infected: Trojan-Downloader.Win32.Homles.bc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\172.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\173.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nve skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\179.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17A.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17B.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17C.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17D.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\18.tmp Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1A.tmp Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\21.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nvf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\23.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nvf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\25.tmp Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\278.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\28.tmp Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nve skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp/b116.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp/b155.exe Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2EA.tmp Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp/b154.exe Infected: Trojan-Downloader.Win32.Agent.kha skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp/b138.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp/b152.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp/UGA6P_0001_N122M2802NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp CAB: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\38.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp/b153.exe Infected: not-a-virus:AdWare.Win32.Insider.d skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3D.tmp Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3E.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3F.tmp Infected: not-a-virus:AdWare.Win32.Insider.d skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\40.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\41.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\44.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\45.tmp Infected: Trojan-Downloader.Win32.Homles.bc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\46.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\47.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\49.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\4A.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\4B.tmp Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\52.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\53.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\57.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58C.tmp Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58E.tmp Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5C.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\64.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\66.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\67.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\77.tmp Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\7D.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\8.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\8D.tmp Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\9.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\A5.tmp Infected: Trojan-Downloader.Win32.Agent.kha skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D.tmp Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D7.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D8.tmp Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP150\A0065003.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP153\change.log Object is locked skipped
C:\WINDOWS\b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\WINDOWS\b104.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\WINDOWS\b104.exe NSIS: infected - 3 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3FBAAED6-AE76-46C6-853E-FC4A509EBD20}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\sscdbhk55.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe NSIS: infected - 2 skipped
C:\WINDOWS\Temp\Perflib_Perfdata_130.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:41:24 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: targettedbanner.biz browser enhancer - {16B435F6-B6CE-4F24-A568-944B27ED919C} - C:\WINDOWS\system32\atgban.dll (file missing)
O2 - BHO: (no name) - {24E9519B-3F70-429B-99BC-4B2B49B96F66} - C:\WINDOWS\system32\iifcdAsQ.dll (file missing)
O2 - BHO: (no name) - {3ACE8464-CEF9-474C-9057-4DDD3821F173} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {83818B68-0D4C-4D16-9FEE-1B61F7A41EA6} - C:\WINDOWS\system32\khfCSlKD.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: {64c367bf-d567-b07a-ca04-fe64981e030b} - {b030e189-46ef-40ac-a70b-765dfb763c46} - C:\WINDOWS\system32\gxhhftxs.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\atgban.dll" DllStart
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [74a271e0] rundll32.exe "C:\WINDOWS\system32\ndwtbjrp.dll",b
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJxdm035YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/DinerDash.1.0.0.94.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: iifcdAsQ - iifcdAsQ.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 12935 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 19, 2008 11:29:58 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/04/2008
Kaspersky Anti-Virus database records: 715483
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 69559
Number of viruses found: 36
Number of infected objects: 140
Number of suspicious objects: 0
Duration of the scan process: 01:03:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\Bree\Application Data\BFGTOOLBAR\bfgtoolbarDLL.zip/bfgtoolbar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.u skipped
C:\Documents and Settings\Bree\Application Data\BFGTOOLBAR\bfgtoolbarDLL.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\cert8.db Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\history.dat Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\key3.db Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\parent.lock Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Bree\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Bree\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064900.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064901.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064902.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064903.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064912.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064914.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064915.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064917.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064918.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064919.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064920.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064921.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064923.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064924.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064926.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064927.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064929.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064931.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064932.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064934.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064935.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064936.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0064937.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065037.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065833.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065834.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\A0065835.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\Bree\DoctorWeb\Quarantine\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\ApplicationHistory\TransferAgent.exe.91f03f4d.ini.inuse Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\BVRP Software\NetWaiting\MoHlog.txt Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_219.wmdb Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebzycnvv.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\History\History.IE5\MSHist012008041920080420\index.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temp\Perflib_Perfdata_dc8.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temp\snapsnet.exe/data0006 Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Documents and Settings\Bree\Local Settings\Temp\snapsnet.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Bree\Local Settings\Temp\~DF9796.tmp Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip/b104.exe Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\718f466754402ac597de014577627f96[1].zip ZIP: infected - 4 skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\snapsnet[1].exe/data0006 Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\F11FUV85\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Bree\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bree\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bree\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\forms.fdb Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\static Object is locked skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\11.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\14.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\171.tmp Infected: Trojan-Downloader.Win32.Homles.bc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\172.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\173.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nve skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\179.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17A.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17B.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17C.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17D.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\18.tmp Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1A.tmp Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\21.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nvf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\23.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nvf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\25.tmp Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\278.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\28.tmp Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.nve skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp/b116.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2C.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp/b155.exe Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2D.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E4.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2E6.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2EA.tmp Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp/b154.exe Infected: Trojan-Downloader.Win32.Agent.kha skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\2F.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp/b138.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp/b152.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\31.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp/UGA6P_0001_N122M2802NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp CAB: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\36.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\38.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp/b153.exe Infected: not-a-virus:AdWare.Win32.Insider.d skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\39.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3A.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3D.tmp Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3E.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\3F.tmp Infected: not-a-virus:AdWare.Win32.Insider.d skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\40.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\41.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\44.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\45.tmp Infected: Trojan-Downloader.Win32.Homles.bc skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\46.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\47.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\49.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\4A.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\4B.tmp Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\52.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\53.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\57.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58C.tmp Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\58E.tmp Infected: Trojan-Downloader.Win32.VB.dsf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5C.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.pil skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\5E.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp NSIS: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\60.tmp CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\64.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\66.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\67.tmp Infected: Trojan-Downloader.Win32.Homles.au skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\77.tmp Infected: Trojan.Win32.BHO.bfl skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\7D.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\8.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\8D.tmp Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\9.tmp Infected: Trojan.Win32.KillAV.rf skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\A5.tmp Infected: Trojan-Downloader.Win32.Agent.kha skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D.tmp Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D7.tmp Infected: Trojan-Downloader.Win32.Agent.lqu skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D8.tmp Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP150\A0065003.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP153\change.log Object is locked skipped
C:\WINDOWS\b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\WINDOWS\b104.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\WINDOWS\b104.exe NSIS: infected - 3 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3FBAAED6-AE76-46C6-853E-FC4A509EBD20}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\sscdbhk55.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.ai skipped
C:\WINDOWS\system32\wii\HTgn1dll.exe NSIS: infected - 2 skipped
C:\WINDOWS\Temp\Perflib_Perfdata_130.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:41:24 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: targettedbanner.biz browser enhancer - {16B435F6-B6CE-4F24-A568-944B27ED919C} - C:\WINDOWS\system32\atgban.dll (file missing)
O2 - BHO: (no name) - {24E9519B-3F70-429B-99BC-4B2B49B96F66} - C:\WINDOWS\system32\iifcdAsQ.dll (file missing)
O2 - BHO: (no name) - {3ACE8464-CEF9-474C-9057-4DDD3821F173} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {83818B68-0D4C-4D16-9FEE-1B61F7A41EA6} - C:\WINDOWS\system32\khfCSlKD.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: {64c367bf-d567-b07a-ca04-fe64981e030b} - {b030e189-46ef-40ac-a70b-765dfb763c46} - C:\WINDOWS\system32\gxhhftxs.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PostSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\atgban.dll" DllStart
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [74a271e0] rundll32.exe "C:\WINDOWS\system32\ndwtbjrp.dll",b
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJxdm035YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/DinerDash.1.0.0.94.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: iifcdAsQ - iifcdAsQ.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 12935 bytes