pilgrim7993
2008-04-22, 04:06
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, April 21, 2008 6:41:26 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 719150
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 86490
Number of viruses found: 16
Number of infected objects: 45
Number of suspicious objects: 0
Duration of the scan process: 02:28:18
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\460C74E7.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\AA4078F0.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped
C:\Documents and Settings\Ken Cates\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\History\History.IE5\MSHist012008042120080422\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temp\~DF4F3C.tmp Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temp\~DF4FD2.tmp Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temporary Internet Files\Content.IE5\0D2XA5IP\install_asm_en[1].exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareExpert.d skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Ken Cates\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AntiSpywareMaster\asm.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareExpert.d skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1B45625C.dll Infected: not-a-virus:AdWare.Win32.BHO.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe/pwdump2/samdump.dll Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe/pwdump2/pwdump2.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/RockXP4.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe Rsrc-Package: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe UPack: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe PE_Patch: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe CryptFF: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2D31092B.htm Infected: Exploit.JS.CVE-2006-1359.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\350F0615.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe/data0002 Infected: Trojan.Win32.VB.ami skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe NSIS: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe CryptFF: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4D280D86.exe Infected: Trojan-Proxy.Win32.Horst.hv skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\56723936.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\56790D2F.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5A6465F7.exe Infected: Trojan.Win32.Regger.s skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F254A32.exe Infected: Trojan.Win32.Dialer.pn skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\73031E6B.exe Infected: Trojan.Win32.Whispy.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S6241A199.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khfGwVmN.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.piv skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe/data0000.cab/THESAM~1.EXE Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe/data0000.cab Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe Rsrc-Package: infected - 2 skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe/data0000.cab/THESAM~1.EXE Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe/data0000.cab Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar RAR: infected - 3 skipped
G:\Hot Software\mirc.6.14.keygen-tsrh\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
G:\Hot Software\mirc.6.14.keygen-tsrh\mirc616.exe mIRC: infected - 1 skipped
G:\Hot Software\Nero\Nero v7.7.5.1\Nero-7.7.5.1_update from nero.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero\Nero v7.7.5.1\Nero-7.7.5.1_update from nero.exe RAR: infected - 1 skipped
G:\Hot Software\Nero\Nero v7.7.5.1\nero7_w_code\Nero-7.7.5.1.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero\Nero v7.7.5.1\nero7_w_code\Nero-7.7.5.1.exe RAR: infected - 1 skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso ISOimage: infected - 3 skipped
G:\Hot Software\PgcEdit\pgcedit.exe/Tcl/work/PGCEDIT/bin/pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
G:\Hot Software\PgcEdit\pgcedit.exe ZIP: infected - 1 skipped
G:\Hot Software\PornMovieGrabberv1.0.4\PMGSetup.exe/file1 Infected: not-a-virus:Porn-Downloader.Win32.Delf.d skipped
G:\Hot Software\PornMovieGrabberv1.0.4\PMGSetup.exe Inno: infected - 1 skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:50:25 PM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
E:\Program Files - AdAware 2007 Free\aawservice.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\ProShowProducer\ScsiAccess.exe
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\windows\SOUNDMAN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\AntiSpywareMaster\asm.exe
C:\windows\system32\ctfmon.exe
E:\Program Files - FormAutoFill\faf.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinTV\Ir.exe
D:\Halllmark Card Studiio 2006\Planner\PLNRnote.exe
C:\windows\system32\rundll32.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\windows\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [osCheck] "E:\Program Files - Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [BMeb83c96c] Rundll32.exe "C:\windows\system32\juoeynmr.dll",s
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [FormAutoFill] E:\Program Files - FormAutoFill\faf.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - S-1-5-18 Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe (User 'Default user')
O4 - Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Event Planner Reminder.lnk = D:\Halllmark Card Studiio 2006\Planner\PLNRnote.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.accuweather.com
O15 - Trusted Zone: http://trials.adobe.com
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.aetn.com
O15 - Trusted Zone: http://www.aetn.org
O15 - Trusted Zone: http://www.aetninternational.com
O15 - Trusted Zone: http://www.amazon.com
O15 - Trusted Zone: http://www.archildrens.org
O15 - Trusted Zone: http://www.bankozarks.com
O15 - Trusted Zone: http://www.billboard.com
O15 - Trusted Zone: http://www.bluegrassbanjo.org
O15 - Trusted Zone: http://www.brickartist.com
O15 - Trusted Zone: http://www.cakewalk.com
O15 - Trusted Zone: http://club.cdfreaks.com
O15 - Trusted Zone: http://www.cdrinfo.com
O15 - Trusted Zone: http://www.cingular.com
O15 - Trusted Zone: http://www.citicards.com
O15 - Trusted Zone: http://www.cyberlink.com
O15 - Trusted Zone: http://www.dennys.com
O15 - Trusted Zone: http://www.dvdshrink.info
O15 - Trusted Zone: http://www.fedex.com
O15 - Trusted Zone: http://www.funmorph.com
O15 - Trusted Zone: http://www.harmony-central.com
O15 - Trusted Zone: http://*.hd-sf.com
O15 - Trusted Zone: http://www.shopping.hp.com
O15 - Trusted Zone: http://us.imdb.com
O15 - Trusted Zone: http://www.imdb.com
O15 - Trusted Zone: http://www.java.com
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://*.kids4truth.com
O15 - Trusted Zone: http://www.landofrost.com
O15 - Trusted Zone: http://www.megavideo.com
O15 - Trusted Zone: http://www.michaelconnelly.com
O15 - Trusted Zone: http://vids.myspace.com
O15 - Trusted Zone: www.nero.com
O15 - Trusted Zone: http://movielicense.netflix.com
O15 - Trusted Zone: http://www.netflix.com
O15 - Trusted Zone: http://www.newegg.com
O15 - Trusted Zone: http://www.officeletter.com
O15 - Trusted Zone: http://blogs.pcworld.com
O15 - Trusted Zone: http://www.pcworld.com
O15 - Trusted Zone: http://www.photodex.com
O15 - Trusted Zone: http://www.primitivequartet.com
O15 - Trusted Zone: http://www.rentawreck.com
O15 - Trusted Zone: http://www.rottentomatoes.com
O15 - Trusted Zone: http://www.sat-gps-locate.com
O15 - Trusted Zone: http://video.sheriff.org
O15 - Trusted Zone: http://www.suegrafton.com
O15 - Trusted Zone: http://www.symantec.com
O15 - Trusted Zone: http://*.systemerrorfixer.com
O15 - Trusted Zone: http://partners.titantv.com
O15 - Trusted Zone: http://www.tomshardware.com
O15 - Trusted Zone: http://*.torrentscan.com
O15 - Trusted Zone: http://www.vhjoe.org
O15 - Trusted Zone: http://www.virustotal.com
O15 - Trusted Zone: http://www.vivalagames.com
O15 - Trusted Zone: http://www.weather.com
O15 - Trusted Zone: http://www.winamp.com
O15 - Trusted Zone: www.yamaha.com
O15 - Trusted Zone: http://www.youtube.com
O15 - Trusted Zone: http://*.youtube.com
O15 - Trusted Zone: http://www.zeallsoft.com
O15 - Trusted IP range: http://216.52.207.219
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Program Files - AdAware 2007 Free\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - E:\Program Files - Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ScsiAccess - Unknown owner - D:\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: (no name) - http://cdn.nflximg.com/us/layout/page_titles/bgvignette/Queue_v2.jpg
--
End of file - 11143 bytes
KASPERSKY ONLINE SCANNER REPORT
Monday, April 21, 2008 6:41:26 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 719150
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 86490
Number of viruses found: 16
Number of infected objects: 45
Number of suspicious objects: 0
Duration of the scan process: 02:28:18
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\460C74E7.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\AA4078F0.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped
C:\Documents and Settings\Ken Cates\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\History\History.IE5\MSHist012008042120080422\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temp\~DF4F3C.tmp Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temp\~DF4FD2.tmp Object is locked skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temporary Internet Files\Content.IE5\0D2XA5IP\install_asm_en[1].exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareExpert.d skipped
C:\Documents and Settings\Ken Cates\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ken Cates\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Ken Cates\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AntiSpywareMaster\asm.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareExpert.d skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1B45625C.dll Infected: not-a-virus:AdWare.Win32.BHO.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe/pwdump2/samdump.dll Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe/pwdump2/pwdump2.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/rock.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab/RockXP4.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe/data0000.cab Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe Rsrc-Package: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe UPack: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe PE_Patch: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2023246B.exe CryptFF: infected - 5 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2D31092B.htm Infected: Exploit.JS.CVE-2006-1359.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\350F0615.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe/data0002 Infected: Trojan.Win32.VB.ami skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe NSIS: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4ADB7ADA.exe CryptFF: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4D280D86.exe Infected: Trojan-Proxy.Win32.Horst.hv skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\56723936.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\56790D2F.exe Infected: Trojan.Win32.Whispy.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5A6465F7.exe Infected: Trojan.Win32.Regger.s skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F254A32.exe Infected: Trojan.Win32.Dialer.pn skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\73031E6B.exe Infected: Trojan.Win32.Whispy.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S6241A199.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khfGwVmN.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.piv skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
E:\Program Files - Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe/data0000.cab/THESAM~1.EXE Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe/data0000.cab Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5\Comic_Life_Deluxe_Editionv1.3.5\CL1.3.5_www.softarchive.net\comiclife-win.exe Rsrc-Package: infected - 2 skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe/data0000.cab/THESAM~1.EXE Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe/data0000.cab Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar/Comic_Life_Deluxe_Editionv1.3.5/CL1.3.5_www.softarchive.net/comiclife-win.exe Infected: Trojan.Win32.Pakes.cgn skipped
G:\Hot Software\Comic Life Deluxe Edition v1.3.5\Comic_Life_Deluxe_Editionv1.3.5.rar RAR: infected - 3 skipped
G:\Hot Software\mirc.6.14.keygen-tsrh\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
G:\Hot Software\mirc.6.14.keygen-tsrh\mirc616.exe mIRC: infected - 1 skipped
G:\Hot Software\Nero\Nero v7.7.5.1\Nero-7.7.5.1_update from nero.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero\Nero v7.7.5.1\Nero-7.7.5.1_update from nero.exe RAR: infected - 1 skipped
G:\Hot Software\Nero\Nero v7.7.5.1\nero7_w_code\Nero-7.7.5.1.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero\Nero v7.7.5.1\nero7_w_code\Nero-7.7.5.1.exe RAR: infected - 1 skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
G:\Hot Software\Nero v8\nue8.0.3\nue8.0.3.0r.iso ISOimage: infected - 3 skipped
G:\Hot Software\PgcEdit\pgcedit.exe/Tcl/work/PGCEDIT/bin/pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
G:\Hot Software\PgcEdit\pgcedit.exe ZIP: infected - 1 skipped
G:\Hot Software\PornMovieGrabberv1.0.4\PMGSetup.exe/file1 Infected: not-a-virus:Porn-Downloader.Win32.Delf.d skipped
G:\Hot Software\PornMovieGrabberv1.0.4\PMGSetup.exe Inno: infected - 1 skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:50:25 PM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
E:\Program Files - AdAware 2007 Free\aawservice.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\ProShowProducer\ScsiAccess.exe
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\windows\SOUNDMAN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\AntiSpywareMaster\asm.exe
C:\windows\system32\ctfmon.exe
E:\Program Files - FormAutoFill\faf.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinTV\Ir.exe
D:\Halllmark Card Studiio 2006\Planner\PLNRnote.exe
C:\windows\system32\rundll32.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\windows\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [osCheck] "E:\Program Files - Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [BMeb83c96c] Rundll32.exe "C:\windows\system32\juoeynmr.dll",s
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [FormAutoFill] E:\Program Files - FormAutoFill\faf.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - S-1-5-18 Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe (User 'Default user')
O4 - Startup: Shortcut to yats32.lnk = C:\Program Files\Dillobits Software\YATS32\yats32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Event Planner Reminder.lnk = D:\Halllmark Card Studiio 2006\Planner\PLNRnote.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.accuweather.com
O15 - Trusted Zone: http://trials.adobe.com
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.aetn.com
O15 - Trusted Zone: http://www.aetn.org
O15 - Trusted Zone: http://www.aetninternational.com
O15 - Trusted Zone: http://www.amazon.com
O15 - Trusted Zone: http://www.archildrens.org
O15 - Trusted Zone: http://www.bankozarks.com
O15 - Trusted Zone: http://www.billboard.com
O15 - Trusted Zone: http://www.bluegrassbanjo.org
O15 - Trusted Zone: http://www.brickartist.com
O15 - Trusted Zone: http://www.cakewalk.com
O15 - Trusted Zone: http://club.cdfreaks.com
O15 - Trusted Zone: http://www.cdrinfo.com
O15 - Trusted Zone: http://www.cingular.com
O15 - Trusted Zone: http://www.citicards.com
O15 - Trusted Zone: http://www.cyberlink.com
O15 - Trusted Zone: http://www.dennys.com
O15 - Trusted Zone: http://www.dvdshrink.info
O15 - Trusted Zone: http://www.fedex.com
O15 - Trusted Zone: http://www.funmorph.com
O15 - Trusted Zone: http://www.harmony-central.com
O15 - Trusted Zone: http://*.hd-sf.com
O15 - Trusted Zone: http://www.shopping.hp.com
O15 - Trusted Zone: http://us.imdb.com
O15 - Trusted Zone: http://www.imdb.com
O15 - Trusted Zone: http://www.java.com
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://*.kids4truth.com
O15 - Trusted Zone: http://www.landofrost.com
O15 - Trusted Zone: http://www.megavideo.com
O15 - Trusted Zone: http://www.michaelconnelly.com
O15 - Trusted Zone: http://vids.myspace.com
O15 - Trusted Zone: www.nero.com
O15 - Trusted Zone: http://movielicense.netflix.com
O15 - Trusted Zone: http://www.netflix.com
O15 - Trusted Zone: http://www.newegg.com
O15 - Trusted Zone: http://www.officeletter.com
O15 - Trusted Zone: http://blogs.pcworld.com
O15 - Trusted Zone: http://www.pcworld.com
O15 - Trusted Zone: http://www.photodex.com
O15 - Trusted Zone: http://www.primitivequartet.com
O15 - Trusted Zone: http://www.rentawreck.com
O15 - Trusted Zone: http://www.rottentomatoes.com
O15 - Trusted Zone: http://www.sat-gps-locate.com
O15 - Trusted Zone: http://video.sheriff.org
O15 - Trusted Zone: http://www.suegrafton.com
O15 - Trusted Zone: http://www.symantec.com
O15 - Trusted Zone: http://*.systemerrorfixer.com
O15 - Trusted Zone: http://partners.titantv.com
O15 - Trusted Zone: http://www.tomshardware.com
O15 - Trusted Zone: http://*.torrentscan.com
O15 - Trusted Zone: http://www.vhjoe.org
O15 - Trusted Zone: http://www.virustotal.com
O15 - Trusted Zone: http://www.vivalagames.com
O15 - Trusted Zone: http://www.weather.com
O15 - Trusted Zone: http://www.winamp.com
O15 - Trusted Zone: www.yamaha.com
O15 - Trusted Zone: http://www.youtube.com
O15 - Trusted Zone: http://*.youtube.com
O15 - Trusted Zone: http://www.zeallsoft.com
O15 - Trusted IP range: http://216.52.207.219
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Program Files - AdAware 2007 Free\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - E:\Program Files - Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ScsiAccess - Unknown owner - D:\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: (no name) - http://cdn.nflximg.com/us/layout/page_titles/bgvignette/Queue_v2.jpg
--
End of file - 11143 bytes