insectoidone
2008-05-15, 07:32
Hello, i posted this topic in the Spybot forum and was told to come here, so i read through the 'before you post' topic and did as it said and did a HJT log and a Kaspersky scan...i know for a fact it is the virtumonde virus and i've given up on trying to fix it, as it seems to be eating my Hard disk space...odd...
Kaspersky log
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 15, 2008 12:30:40 AM
Operating System: Microsoft Windows Vista Home Edition, Service Pack 1 (Build 6001)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/05/2008
Kaspersky Anti-Virus database records: 773912
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 115979
Number of viruses found: 9
Number of infected objects: 59
Number of suspicious objects: 0
Duration of the scan process: 02:30:25
Infected Object Name / Virus Name / Last Action
C:\$RECYCLE.BIN\S-1-5-21-2560033090-1611507104-3571004108-1000\$RAWFIKC\Prodigy - The Q B Killa Tape (2008).exe/data0002 Infected: Trojan.Win32.Monder.gen skipped
C:\$RECYCLE.BIN\S-1-5-21-2560033090-1611507104-3571004108-1000\$RAWFIKC\Prodigy - The Q B Killa Tape (2008).exe NSIS: infected - 1 skipped
C:\Program Files\Common Files\microsoft shared\MSInfo\Netlog.exe Infected: Backdoor.Win32.Hupigon.atyo skipped
C:\Program Files\outlook\p.zip/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Program Files\outlook\p.zip ZIP: infected - 1 skipped
C:\Program Files\outlook\v.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\ProgramData\CyberLink\TinyDB\EPGSignal Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\Schedule Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f8381470490e5aaca556386c091a2ce_4bb79e9b-e854-4035-8f74-ef695f887196 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.309.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.309.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy312.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfB3A5.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfB3A6.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008051420080515\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\css4[2] Infected: Trojan.Win32.Monder.dg skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\idkfa[1] Infected: Trojan.Win32.Monder.do skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.quk skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[4] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[5] Infected: Trojan.Win32.Zapchast.gr skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\hctp[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\moorate[1] Infected: Trojan.Win32.KillAV.rf skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\query[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\hctp[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\query[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TM.blf Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows Defender\FileTracker\{645663E4-2040-4ADE-90D9-36EBA7F54A2D} Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\Zac\AppData\Local\Temp\ehmsas.txt Object is locked skipped
C:\Users\Zac\AppData\Local\Temp\tmp00008870 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000aacf Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000adbb Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000b28c Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000b94f Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000bbfe Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000bf58 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c35d Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c86c Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c8f9 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000cccf Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000d1a0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000db8f Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00015aac Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001b6d0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001cb49 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001cba7 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001eee0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001f7a6 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp002177de Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp005e82a8 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp007567e8 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00bd9466 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00f4af37 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0186f3a9 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp026e3925 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\cert8.db Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\history.dat Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\key3.db Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\parent.lock Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\search.sqlite Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\Zac\ntuser.dat Object is locked skipped
C:\Users\Zac\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Zac\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TM.blf Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\amlrgjrp.dll_old Infected: Trojan.Win32.Monder.do skipped
C:\Windows\System32\bgmmuqie.dll_old Infected: Trojan.Win32.Monder.di skipped
C:\Windows\System32\bnorcqtv.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\bxilsffb.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.blf Object is locked skipped
C:\Windows\System32\conhoifp.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\dnpqwikw.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\geBtSLeF.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\ombaleru.dll_old Infected: Trojan.Win32.Monder.di skipped
C:\Windows\System32\qsesmcar.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Metrics.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\System32\xtnmuesw.dll_old Infected: Trojan.Win32.Monder.do skipped
C:\Windows\System32\xxyawttq.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Windows\System32\yunvatfx.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
D:\System Volume Information\Desktop.ini Object is locked skipped
D:\System Volume Information\Folder.htt Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\Protect.ed Object is locked skipped
Scan process completed.
HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:25:53 AM, on 5/15/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP Optical 4 Button USB Mouse\Kmaestro.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Zac\Desktop\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {15140DAA-FF75-4C23-9897-61D081A26D0A} - C:\Windows\system32\xxyawttq.dll
O2 - BHO: (no name) - {3713F9EE-C059-4540-B697-987EF263A088} - C:\Windows\system32\geBtSLeF.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\HP Optical 4 Button USB Mouse\KMaestro.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\geBtSLeF.dll,#1
O4 - HKLM\..\Run: [61f9bcd5] rundll32.exe "C:\Windows\system32\pchegrll.dll",b
O4 - HKLM\..\Run: [BM62ca8f49] Rundll32.exe "C:\Windows\system32\exusnwsu.dll",s
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4698] command /c del "C:\Windows\System32\aawlgvni.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1715] cmd /c del "C:\Windows\System32\aawlgvni.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5480] command /c del "C:\Windows\System32\amlrgjrp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8020] cmd /c del "C:\Windows\System32\amlrgjrp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4927] command /c del "C:\Windows\System32\bgmmuqie.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2727] cmd /c del "C:\Windows\System32\bgmmuqie.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5469] command /c del "C:\Windows\System32\ldmtwaej.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9912] cmd /c del "C:\Windows\System32\ldmtwaej.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2246] command /c del "C:\Windows\System32\ombaleru.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1140] cmd /c del "C:\Windows\System32\ombaleru.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8223] command /c del "C:\Windows\System32\uignibas.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2999] cmd /c del "C:\Windows\System32\uignibas.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1067] command /c del "C:\Windows\System32\xtnmuesw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8298] cmd /c del "C:\Windows\System32\xtnmuesw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6146] command /c del "C:\Windows\System32\xxyawttq.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7710] cmd /c del "C:\Windows\System32\xxyawttq.dll"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
O23 - Service: Windows Network Log (Windows Network Log Manage) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\Netlog.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9632 bytes
Kaspersky log
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 15, 2008 12:30:40 AM
Operating System: Microsoft Windows Vista Home Edition, Service Pack 1 (Build 6001)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/05/2008
Kaspersky Anti-Virus database records: 773912
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 115979
Number of viruses found: 9
Number of infected objects: 59
Number of suspicious objects: 0
Duration of the scan process: 02:30:25
Infected Object Name / Virus Name / Last Action
C:\$RECYCLE.BIN\S-1-5-21-2560033090-1611507104-3571004108-1000\$RAWFIKC\Prodigy - The Q B Killa Tape (2008).exe/data0002 Infected: Trojan.Win32.Monder.gen skipped
C:\$RECYCLE.BIN\S-1-5-21-2560033090-1611507104-3571004108-1000\$RAWFIKC\Prodigy - The Q B Killa Tape (2008).exe NSIS: infected - 1 skipped
C:\Program Files\Common Files\microsoft shared\MSInfo\Netlog.exe Infected: Backdoor.Win32.Hupigon.atyo skipped
C:\Program Files\outlook\p.zip/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Program Files\outlook\p.zip ZIP: infected - 1 skipped
C:\Program Files\outlook\v.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\ProgramData\CyberLink\TinyDB\EPGSignal Object is locked skipped
C:\ProgramData\CyberLink\TinyDB\Schedule Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f8381470490e5aaca556386c091a2ce_4bb79e9b-e854-4035-8f74-ef695f887196 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.309.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.309.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010020.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy312.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfB3A5.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfB3A6.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008051420080515\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\css4[2] Infected: Trojan.Win32.Monder.dg skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GOG4ER4R\idkfa[1] Infected: Trojan.Win32.Monder.do skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.quk skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[4] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ8XISZF\css4[5] Infected: Trojan.Win32.Zapchast.gr skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\hctp[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\moorate[1] Infected: Trojan.Win32.KillAV.rf skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TNXVD0M5\query[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\css4[3] Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\hctp[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V328R7FS\query[1] Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TM.blf Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows\UsrClass.dat{e1120885-3dc3-11dc-8d6c-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Zac\AppData\Local\Microsoft\Windows Defender\FileTracker\{645663E4-2040-4ADE-90D9-36EBA7F54A2D} Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\Zac\AppData\Local\Mozilla\Firefox\Profiles\qm1q5j3q.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\Zac\AppData\Local\Temp\ehmsas.txt Object is locked skipped
C:\Users\Zac\AppData\Local\Temp\tmp00008870 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000aacf Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000adbb Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000b28c Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000b94f Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000bbfe Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000bf58 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c35d Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c86c Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000c8f9 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000cccf Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000d1a0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0000db8f Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00015aac Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001b6d0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001cb49 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001cba7 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001eee0 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0001f7a6 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp002177de Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp005e82a8 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp007567e8 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00bd9466 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp00f4af37 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp0186f3a9 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Local\Temp\tmp026e3925 Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Zac\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\cert8.db Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\history.dat Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\key3.db Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\parent.lock Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\search.sqlite Object is locked skipped
C:\Users\Zac\AppData\Roaming\Mozilla\Firefox\Profiles\qm1q5j3q.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\Zac\ntuser.dat Object is locked skipped
C:\Users\Zac\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Zac\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TM.blf Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Zac\ntuser.dat{ed1fc5bf-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{ed1fc5bb-1b98-11dd-bf97-001a6b84a980}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\amlrgjrp.dll_old Infected: Trojan.Win32.Monder.do skipped
C:\Windows\System32\bgmmuqie.dll_old Infected: Trojan.Win32.Monder.di skipped
C:\Windows\System32\bnorcqtv.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\bxilsffb.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{ed1fc5a2-1b98-11dd-bf97-001a6b84a980}.TxR.blf Object is locked skipped
C:\Windows\System32\conhoifp.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\dnpqwikw.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\geBtSLeF.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\ombaleru.dll_old Infected: Trojan.Win32.Monder.di skipped
C:\Windows\System32\qsesmcar.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Metrics.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\System32\xtnmuesw.dll_old Infected: Trojan.Win32.Monder.do skipped
C:\Windows\System32\xxyawttq.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Windows\System32\yunvatfx.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
D:\System Volume Information\Desktop.ini Object is locked skipped
D:\System Volume Information\Folder.htt Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\Protect.ed Object is locked skipped
Scan process completed.
HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:25:53 AM, on 5/15/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP Optical 4 Button USB Mouse\Kmaestro.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Zac\Desktop\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {15140DAA-FF75-4C23-9897-61D081A26D0A} - C:\Windows\system32\xxyawttq.dll
O2 - BHO: (no name) - {3713F9EE-C059-4540-B697-987EF263A088} - C:\Windows\system32\geBtSLeF.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\HP Optical 4 Button USB Mouse\KMaestro.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\geBtSLeF.dll,#1
O4 - HKLM\..\Run: [61f9bcd5] rundll32.exe "C:\Windows\system32\pchegrll.dll",b
O4 - HKLM\..\Run: [BM62ca8f49] Rundll32.exe "C:\Windows\system32\exusnwsu.dll",s
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4698] command /c del "C:\Windows\System32\aawlgvni.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1715] cmd /c del "C:\Windows\System32\aawlgvni.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5480] command /c del "C:\Windows\System32\amlrgjrp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8020] cmd /c del "C:\Windows\System32\amlrgjrp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4927] command /c del "C:\Windows\System32\bgmmuqie.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2727] cmd /c del "C:\Windows\System32\bgmmuqie.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5469] command /c del "C:\Windows\System32\ldmtwaej.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9912] cmd /c del "C:\Windows\System32\ldmtwaej.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2246] command /c del "C:\Windows\System32\ombaleru.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1140] cmd /c del "C:\Windows\System32\ombaleru.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8223] command /c del "C:\Windows\System32\uignibas.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2999] cmd /c del "C:\Windows\System32\uignibas.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1067] command /c del "C:\Windows\System32\xtnmuesw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8298] cmd /c del "C:\Windows\System32\xtnmuesw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6146] command /c del "C:\Windows\System32\xxyawttq.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7710] cmd /c del "C:\Windows\System32\xxyawttq.dll"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
O23 - Service: Windows Network Log (Windows Network Log Manage) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\Netlog.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9632 bytes