rosemary2468
2008-05-11, 17:40
Hello. I hope someone can help. On running Spybot it now freezes at the following point: "Running bot-check (128840/150537: Virtumonde.dll). The scan moves no further and I have to use Task Manager to quit the application. I have run Kaspersky on-line virus scanner and it states I have 3 viruses. AVG does not pick these up! I have read previous thread posted by griffin 99 on 07/05/08 and have run avz4 but when I try to attach the AVZ4 .htm log I am told it is an invalid file type. HJT and Kaspersky logs below. Any help would be very much appreciated. Many thanks.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:40:35, on 11/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\My Kazaa Gold\MyGoldKazaa.exe
C:\Program Files\My Kazaa Gold\giFT\giFTl.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [My Kazaa Gold] C:\Program Files\My Kazaa Gold\MyGoldKazaa.exe /hide
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {254AA86E-5655-4518-AA87-185D7CC41801} (LogMeIn Rescue Technician Console) - https://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197411738875
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 9872 bytes
----------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, May 11, 2008 3:05:07 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/05/2008
Kaspersky Anti-Virus database records: 755935
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 97082
Number of viruses found: 3
Number of infected objects: 14
Number of suspicious objects: 29
Duration of the scan process: 01:32:06
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Rose\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped
C:\Documents and Settings\Rose\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx MailMSOutlook5: suspicious - 2 skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml Mail: suspicious - 2 skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\MSHist012008051020080511\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\MSHist012008051120080512\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temp\~DF4A34.tmp Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temp\~DF4A3F.tmp Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rose\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Rose\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterInstance.lock Object is locked skipped
C:\Program Files\My Kazaa Gold\giFT\conf\giftd.log Object is locked skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc191.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak MailMSOutlook5: suspicious - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5D4641A4-9BA3-4DC4-AE5C-839C4C458301}\RP174\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{1532154B-7A1A-437B-B456-5FE5EBB41698}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\mail backup\Terrastar.dbx/[From "daugustine" <daugustine@email.msn.com>][Date Thu, 2 Mar 2000 16:35:29 -0800]/UNNAMED/A-Z Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "daugustine" <daugustine@email.msn.com>][Date Thu, 2 Mar 2000 16:35:29 -0800]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Mon, 29 May 2000 09:35:49 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Mon, 29 May 2000 09:35:49 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Tue, 30 May 2000 21:30:30 +0100]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Tue, 30 May 2000 21:30:30 +0100]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 14 Jun 2000 02:07:36 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 14 Jun 2000 02:07:36 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Wed, 14 Jun 2000 15:33:06 +0200]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Wed, 14 Jun 2000 15:33:06 +0200]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 19 Jul 2000 07:42:23 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 19 Jul 2000 07:42:23 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx MailMSOutlook5: infected - 12 skipped
F:\mail backup\Ebay-Paypal.dbx/[From eBay <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
F:\mail backup\Ebay-Paypal.dbx MailMSOutlook5: suspicious - 1 skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:40:35, on 11/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\My Kazaa Gold\MyGoldKazaa.exe
C:\Program Files\My Kazaa Gold\giFT\giFTl.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [My Kazaa Gold] C:\Program Files\My Kazaa Gold\MyGoldKazaa.exe /hide
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {254AA86E-5655-4518-AA87-185D7CC41801} (LogMeIn Rescue Technician Console) - https://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197411738875
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 9872 bytes
----------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, May 11, 2008 3:05:07 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/05/2008
Kaspersky Anti-Virus database records: 755935
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 97082
Number of viruses found: 3
Number of infected objects: 14
Number of suspicious objects: 29
Duration of the scan process: 01:32:06
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Rose\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped
C:\Documents and Settings\Rose\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Identities\{FCEBE413-7EA6-475F-9644-A6FA947415C9}\Microsoft\Outlook Express\Ebay-Paypal (1).dbx MailMSOutlook5: suspicious - 2 skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\Rose\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Ebay-Paypal\61AE5012-0000005D.eml Mail: suspicious - 2 skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\MSHist012008051020080511\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\History\History.IE5\MSHist012008051120080512\index.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temp\~DF4A34.tmp Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temp\~DF4A3F.tmp Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Rose\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rose\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Rose\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterInstance.lock Object is locked skipped
C:\Program Files\My Kazaa Gold\giFT\conf\giftd.log Object is locked skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc104.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc151.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc191.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc198.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc236.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc25.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc290.bak MailMSOutlook5: suspicious - 2 skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak/[From "eBay" <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/UNNAMED Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\RECYCLER\S-1-5-21-1645522239-1500820517-839522115-1003\Dc62.bak MailMSOutlook5: suspicious - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5D4641A4-9BA3-4DC4-AE5C-839C4C458301}\RP174\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{1532154B-7A1A-437B-B456-5FE5EBB41698}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\mail backup\Terrastar.dbx/[From "daugustine" <daugustine@email.msn.com>][Date Thu, 2 Mar 2000 16:35:29 -0800]/UNNAMED/A-Z Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "daugustine" <daugustine@email.msn.com>][Date Thu, 2 Mar 2000 16:35:29 -0800]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Mon, 29 May 2000 09:35:49 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Mon, 29 May 2000 09:35:49 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Tue, 30 May 2000 21:30:30 +0100]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Tue, 30 May 2000 21:30:30 +0100]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 14 Jun 2000 02:07:36 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 14 Jun 2000 02:07:36 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Wed, 14 Jun 2000 15:33:06 +0200]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "David Evans" <dpe@azleisure.com>][Date Wed, 14 Jun 2000 15:33:06 +0200]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 19 Jul 2000 07:42:23 PDT]/UNNAMED/DELTA.003.doc Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx/[From "david augustine" <dmaugustine@hotmail.com>][Date Wed, 19 Jul 2000 07:42:23 PDT]/UNNAMED Infected: Virus.MSWord.Ethan skipped
F:\mail backup\Terrastar.dbx MailMSOutlook5: infected - 12 skipped
F:\mail backup\Ebay-Paypal.dbx/[From eBay <watchnotice@ebay.co.uk>][Date Sun, 16 Apr 2006 07:29:41 PDT]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
F:\mail backup\Ebay-Paypal.dbx MailMSOutlook5: suspicious - 1 skipped
Scan process completed.