Naefpress
2008-04-30, 17:39
Hi, We're getting a pop-up that mimics a windows warning about a virus (poorly done I might add). From what I've sqeezed out of the other users on this comp, sounds like it was picked up exactly like your description of the Zlob Trojan sticky thread. Please help! Thank you so much for taking the time to look at this. Spybot came up clean (it's updated and I'm using version 1.5.2) , but here are my Kapersky and HJT:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 30, 2008 9:58:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/04/2008
Kaspersky Anti-Virus database records: 725749
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
N:\
Scan Statistics:
Total number of scanned objects: 109263
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 02:11:08
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Bernie\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\ApplicationHistory\NA1Msgr.exe.d8c085f6.ini.inuse Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\History\History.IE5\MSHist012008042520080426\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temp\jar_cache56494.tmp Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temp\Perflib_Perfdata_4a4.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bernie\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\New Folder\ntuser.dat Object is locked skipped
C:\Documents and Settings\New Folder\ntuser.dat.LOG Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\004c5a685f9cd6899b1b3ebf3e0472ef_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\042a92f3283f3f6d6c6db654ac5d050e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\060c6b348c1d297b20792ea41a92bf2f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b45ee31c8c7d721bd509fd8dcd106a2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ccb7d249fe786d57ba68faaec7d198a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ceec3d2b856427a2147c909377478a5_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11d58f5ce6c60b9e504048bddac1d903_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\126ac10bc6c60763603b65ffdfe61af9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18902f7fa15f1fa99b82baa514271a76_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a232fed38a75a3a4dee930730cbee0b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d8fd7ab62a70eacaeaf4acbd32d0ad1_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f428bb2df2b289265e29d77dfef2498_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\207d1005d97b72909e4042992f116fd2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2119ea7715b1b40709d12cd5ea30ce09_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27833a9f9390e9690ed80f167b3b6c4c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b89f3b134c1126aa8d41dab2f36e9d0_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f6f4d023aee126ed504d21fad802fdb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3077d5cadd3c2c5492e5b8972019dcd4_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\353c27bb50edb76f47c38851a848a11a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3548f32b44efda3e5c3c9e09cc4405c9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3822629ea5f07689190f89b02ba469b3_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\383421f32ad00173635337f805bd686f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3983e62b58b2dc62302350d10ba25789_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f9d8efd35d0a8304b6ccebc2925e93e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\427fa3a0c3eeca5954ccf933beda4b12_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42fdf8bc267edf98c54bae2b7312744b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\437f3055c58e9c21cf27aa115ea6a75c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43c42aa7ac75912f91832886de7930e0_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4686ee8fa638b2741915ab7d6baafa8b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47f87d0beb390db032aba7124a47d691_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4965d227f39f715a5c35d10de66b6cfb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\496b7b1bf84bfec5137caf1eb022aefd_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5092fa96e344bd941ed0df6e1de965d2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53f954600aff6d992237395cf1eaac25_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\547d3150f056dccff4394c0d2c1e8f90_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54c039398bd9ecc39f8261eda4df010a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55d95629f2538385fadeb3c8e7889f87_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57df21851ae65e43d4aa7e4a72198034_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a95c427110b188076966feac6cd6477_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b135393c41c30452be69ce165ecb1c7_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b1ef1d6b549064ec2547feeb52e8125_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b80b779dd5f82f711a7b22e89b7845a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\660f9e8a75db667cd108efcf154e4bf3_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6627c115624ae2a36889474614b3921b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\673423b51518cdef9c2eae90aa73218a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b358140549410808309faa5a7e34aed_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f1c77081c2a299b9d6c01f8cbb21ff8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7850fe3003b0dda815b531db257bb292_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7abed422b7f1d0ff6fd74f5887dc3058_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b9039a2083ff4d68e3e6a383e4190ed_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d24629d8f6d7bb3b48c5813ee9ff786_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80fb73c0c29cac16c242c38f985761da_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\848d237fbea6941b124a3c2b6880db77_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87a83d737673b78168b822fd8b884dac_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89b28c95831082de9bf229fe98ff3808_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98f68de657a6a1ae507d68211d70fa78_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\999bd340bd37f909095e3494e9dd40f2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b19b00b1ada4c28284e30f546abce4f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bdc218ec02ad1299e79fc882f1ac491_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c0cbde5843bc923ad3abdd610a24355_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c11f87d02a0274a9bb0f4d64bc842c7_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c5f52047efc86222daf6c4f6af871bd_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2348344b779b13a0888e526b0c93349_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae1870ca32acdc7e46f64312916500e5_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b31403ed3ff5946a224de6a7af3435eb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b320c82646ab2c0044391ee1bac84e4e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b401f3d26fb5c1fb157db3326c513fd2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7532444c24b44a50715c260c785d5f8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd03360bb40f4ec95ac27b57b421ce84_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be87a54f9b849fc85cd11b7baf479e19_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c000044155a39c2d79083ce6089da0de_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3810d0fae43aeb480315ce350985377_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7ccf6bdc231074a3bac229720541d37_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c839a5813c6e7c8e98cdd71807eed6c9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc31c2bf5149aa6354ed5c8ba16f043e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc744a2b0deb418204f0c46834ceb05f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da82038eb8d6165dc761349c8324086a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daf5ac339f7ea51ac4cbaa664083ddf8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dafd11b48a41733a3134c9f2f883f95d_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df74ba4348985a7a80845abeb7841201_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e01dda80244f2308b96c0479a4b3b694_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3d8245e95313c57f02fb352fa469cdb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3c8ac94166311b9bedd5460ca60f840_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faab9c179b8cc8789ebb12d297137d50_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbab8cdee73668c127bbeb0ba5fed762_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd228c132f27a0e2c7726991d4881b9c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff1c1fbf3ad2a0e92154775c332a745c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffb48887754eaebe1eb513359e19db27_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\G1EBW56N\mob[1].htm Infected: Trojan-Downloader.JS.Agent.eo skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Q1TQB29C\zpopup[2].cgi Infected: Exploit.HTML.UrlSpoof.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\master.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\mastlog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\model.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\modellog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\tempdb.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\templog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\upswsdb.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\upswsdb.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\LOG\ERRORLOG Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_604.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
N:\UPS\WSTD\INMAIL\20080425.219 Object is locked skipped
N:\UPS\WSTD\wstdShipMain.ini Object is locked skipped
N:\UPS\WSTD\XML\wstdRequiredFields.xml Object is locked skipped
N:\UPS\WSTD\XML\wstdTabOrder.xml Object is locked skipped
Scan process completed.
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:12 AM, on 4/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\alg.exe
C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\UPS\WSTD\Messages\WSTDMessaging.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Video - {414B0283-2228-4F26-8BB3-C2211FA99223} - C:\WINDOWS\ksol.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Autodesk DWF - {F03966D3-8EA0-47b4-BBE0-85BFE6CBC8AC} - C:\Program Files\Autodesk\Autodesk DWF Writer\DWF Addin\DWFIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PDF4 Registry Controller] "C:\Program Files\ScanSoft\PDF Converter 4\\RegistryController.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ScanSoft PDF Converter 4-reminder] "C:\Program Files\ScanSoft\PDF Converter 4\Ereg\ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Converter\4\Ereg\ereg.ini"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\Messages\WSTDMessaging.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O8 - Extra context menu item: Open with ScanSoft PDF Converter 4.0 - res://C:\Program Files\ScanSoft\PDF Converter 4\cnvres_eng.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5-windows-i586.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9482 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 30, 2008 9:58:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/04/2008
Kaspersky Anti-Virus database records: 725749
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
N:\
Scan Statistics:
Total number of scanned objects: 109263
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 02:11:08
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Bernie\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\ApplicationHistory\NA1Msgr.exe.d8c085f6.ini.inuse Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\History\History.IE5\MSHist012008042520080426\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temp\jar_cache56494.tmp Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temp\Perflib_Perfdata_4a4.dat Object is locked skipped
C:\Documents and Settings\Bernie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bernie\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Bernie\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\New Folder\ntuser.dat Object is locked skipped
C:\Documents and Settings\New Folder\ntuser.dat.LOG Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\004c5a685f9cd6899b1b3ebf3e0472ef_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\042a92f3283f3f6d6c6db654ac5d050e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\060c6b348c1d297b20792ea41a92bf2f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b45ee31c8c7d721bd509fd8dcd106a2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ccb7d249fe786d57ba68faaec7d198a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ceec3d2b856427a2147c909377478a5_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11d58f5ce6c60b9e504048bddac1d903_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\126ac10bc6c60763603b65ffdfe61af9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18902f7fa15f1fa99b82baa514271a76_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a232fed38a75a3a4dee930730cbee0b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d8fd7ab62a70eacaeaf4acbd32d0ad1_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f428bb2df2b289265e29d77dfef2498_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\207d1005d97b72909e4042992f116fd2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2119ea7715b1b40709d12cd5ea30ce09_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\27833a9f9390e9690ed80f167b3b6c4c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b89f3b134c1126aa8d41dab2f36e9d0_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f6f4d023aee126ed504d21fad802fdb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3077d5cadd3c2c5492e5b8972019dcd4_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\353c27bb50edb76f47c38851a848a11a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3548f32b44efda3e5c3c9e09cc4405c9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3822629ea5f07689190f89b02ba469b3_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\383421f32ad00173635337f805bd686f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3983e62b58b2dc62302350d10ba25789_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f9d8efd35d0a8304b6ccebc2925e93e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\427fa3a0c3eeca5954ccf933beda4b12_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42fdf8bc267edf98c54bae2b7312744b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\437f3055c58e9c21cf27aa115ea6a75c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43c42aa7ac75912f91832886de7930e0_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4686ee8fa638b2741915ab7d6baafa8b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47f87d0beb390db032aba7124a47d691_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4965d227f39f715a5c35d10de66b6cfb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\496b7b1bf84bfec5137caf1eb022aefd_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5092fa96e344bd941ed0df6e1de965d2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53f954600aff6d992237395cf1eaac25_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\547d3150f056dccff4394c0d2c1e8f90_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54c039398bd9ecc39f8261eda4df010a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55d95629f2538385fadeb3c8e7889f87_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57df21851ae65e43d4aa7e4a72198034_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a95c427110b188076966feac6cd6477_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b135393c41c30452be69ce165ecb1c7_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b1ef1d6b549064ec2547feeb52e8125_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b80b779dd5f82f711a7b22e89b7845a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\660f9e8a75db667cd108efcf154e4bf3_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6627c115624ae2a36889474614b3921b_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\673423b51518cdef9c2eae90aa73218a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b358140549410808309faa5a7e34aed_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f1c77081c2a299b9d6c01f8cbb21ff8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7850fe3003b0dda815b531db257bb292_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7abed422b7f1d0ff6fd74f5887dc3058_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b9039a2083ff4d68e3e6a383e4190ed_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d24629d8f6d7bb3b48c5813ee9ff786_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80fb73c0c29cac16c242c38f985761da_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\848d237fbea6941b124a3c2b6880db77_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87a83d737673b78168b822fd8b884dac_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89b28c95831082de9bf229fe98ff3808_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98f68de657a6a1ae507d68211d70fa78_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\999bd340bd37f909095e3494e9dd40f2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9b19b00b1ada4c28284e30f546abce4f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bdc218ec02ad1299e79fc882f1ac491_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c0cbde5843bc923ad3abdd610a24355_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c11f87d02a0274a9bb0f4d64bc842c7_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c5f52047efc86222daf6c4f6af871bd_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2348344b779b13a0888e526b0c93349_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae1870ca32acdc7e46f64312916500e5_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b31403ed3ff5946a224de6a7af3435eb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b320c82646ab2c0044391ee1bac84e4e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b401f3d26fb5c1fb157db3326c513fd2_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7532444c24b44a50715c260c785d5f8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd03360bb40f4ec95ac27b57b421ce84_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be87a54f9b849fc85cd11b7baf479e19_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c000044155a39c2d79083ce6089da0de_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3810d0fae43aeb480315ce350985377_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7ccf6bdc231074a3bac229720541d37_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c839a5813c6e7c8e98cdd71807eed6c9_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc31c2bf5149aa6354ed5c8ba16f043e_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc744a2b0deb418204f0c46834ceb05f_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da82038eb8d6165dc761349c8324086a_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\daf5ac339f7ea51ac4cbaa664083ddf8_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dafd11b48a41733a3134c9f2f883f95d_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df74ba4348985a7a80845abeb7841201_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e01dda80244f2308b96c0479a4b3b694_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3d8245e95313c57f02fb352fa469cdb_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3c8ac94166311b9bedd5460ca60f840_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\faab9c179b8cc8789ebb12d297137d50_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbab8cdee73668c127bbeb0ba5fed762_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd228c132f27a0e2c7726991d4881b9c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff1c1fbf3ad2a0e92154775c332a745c_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffb48887754eaebe1eb513359e19db27_b7c9c0a8-0cb4-42e9-a876-c443f3590528 Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\G1EBW56N\mob[1].htm Infected: Trojan-Downloader.JS.Agent.eo skipped
C:\My Backup -- 06-09-05 0246PM\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Q1TQB29C\zpopup[2].cgi Infected: Exploit.HTML.UrlSpoof.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\master.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\mastlog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\model.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\modellog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\tempdb.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\templog.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\upswsdb.ldf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Data\upswsdb.mdf Object is locked skipped
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\LOG\ERRORLOG Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_604.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
N:\UPS\WSTD\INMAIL\20080425.219 Object is locked skipped
N:\UPS\WSTD\wstdShipMain.ini Object is locked skipped
N:\UPS\WSTD\XML\wstdRequiredFields.xml Object is locked skipped
N:\UPS\WSTD\XML\wstdTabOrder.xml Object is locked skipped
Scan process completed.
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:12 AM, on 4/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\alg.exe
C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\UPS\WSTD\Messages\WSTDMessaging.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Video - {414B0283-2228-4F26-8BB3-C2211FA99223} - C:\WINDOWS\ksol.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Autodesk DWF - {F03966D3-8EA0-47b4-BBE0-85BFE6CBC8AC} - C:\Program Files\Autodesk\Autodesk DWF Writer\DWF Addin\DWFIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PDF4 Registry Controller] "C:\Program Files\ScanSoft\PDF Converter 4\\RegistryController.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ScanSoft PDF Converter 4-reminder] "C:\Program Files\ScanSoft\PDF Converter 4\Ereg\ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PDF Converter\4\Ereg\ereg.ini"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\Messages\WSTDMessaging.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O8 - Extra context menu item: Open with ScanSoft PDF Converter 4.0 - res://C:\Program Files\ScanSoft\PDF Converter 4\cnvres_eng.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5-windows-i586.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9482 bytes