rinkrat
2008-06-04, 17:42
Here is the Hijack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:37:30 AM, on 6/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.letsgokings.com/bbs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WeatherClock] C:\Program Files\Weather Clock\WeatherClock.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill form using Password Manager XP - C:\Program Files\Password Manager XP\InsPwd.htm
O8 - Extra context menu item: Generate password using Password Manager XP - C:\Program Files\Password Manager XP\GenPwd.htm
O8 - Extra context menu item: Save form data to Password Manager XP - C:\Program Files\Password Manager XP\SavePwd.htm
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Password Manager XP - {7379d689-cc96-451d-b46e-6bbe4ca6b02d} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108173664123
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125851434899
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - http://www.photodex.com/pxplay.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11648 bytes
Kaspersy log
------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 7:33:38 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/06/2008
Kaspersky Anti-Virus database records: 827768
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 268389
Number of viruses found: 20
Number of infected objects: 78
Number of suspicious objects: 0
Duration of the scan process: 05:05:51
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-06-03_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\114F5CE0.tmp Infected: Flooder.Linux.Nestea.c skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\141271F4.tmp Infected: DoS.Linux.Kod.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\180F2ED2.tmp Infected: Flooder.Linux.Small.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\199766B6.exe Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FDF68F0.exe Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26CE502B.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27AC69AB.exe Infected: Trojan.Win32.Dialer.it skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A4A7CC6.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BC82D22.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BCF011B.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C863051.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40B015AF.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\483255D2.tmp Infected: Email-Worm.Win32.Klez.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4ACD0C18.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4AD13615.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E5F08F3.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5157719E.emf Infected: Trojan-Downloader.Win32.Agent.acd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\566B342B.tmp Infected: Email-Worm.Win32.Klez.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57554FB9.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5DD70CD1.tmp Infected: Spoofer.Linux.Small.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BC7629D.tmp Infected: Exploit.Linux.Bonk.c skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\21410A55.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\5E35E9AC.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\All Users\ntuser.dat Object is locked skipped
C:\Documents and Settings\All Users\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\cert8.db Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\history.dat Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\key3.db Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc ZIP: infected - 2 skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Me\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Feeds\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\History\History.IE5\MSHist012008060320080604\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\FBBYVSMN\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Me\ntuser.dat Object is locked skipped
C:\Documents and Settings\Me\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\poop\!work\hacked file\sdf.txt Infected: Exploit.PHP.Deftool.e skipped
C:\poop\byXQKbaX.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/is155083.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip ZIP: infected - 8 skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip ZIP: infected - 8 skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe Rsrc-Package: infected - 7 skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip ZIP: infected - 8 skipped
C:\Program Files\CB Bar\cbbar.dll Infected: Trojan-Clicker.Win32.Delf.bc skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080603-193936-847.dll Infected: Trojan.Win32.Monder.lm skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080603-215745-112.dll Infected: Trojan.Win32.Monder.lm skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5541\NAV2007RETAIL_XP_VISTA32.64\NAV07RT.exe Infected: Trojan-Dropper.Win32.Agent.cuj skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe/data0000.cab/is200079.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar RAR: infected - 3 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\A0207141.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\A0207227.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\byXNeCst.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ddcArSIc.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\ddcCSKAt.dll Infected: Trojan.Win32.Monder.lm skipped
C:\WINDOWS\system32\drivers\etc\Hosts.bak Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\JET2FC3.tmp Object is locked skipped
C:\WINDOWS\temp\JET460A.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Please help asap... Thanks for this. :)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:37:30 AM, on 6/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.letsgokings.com/bbs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WeatherClock] C:\Program Files\Weather Clock\WeatherClock.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill form using Password Manager XP - C:\Program Files\Password Manager XP\InsPwd.htm
O8 - Extra context menu item: Generate password using Password Manager XP - C:\Program Files\Password Manager XP\GenPwd.htm
O8 - Extra context menu item: Save form data to Password Manager XP - C:\Program Files\Password Manager XP\SavePwd.htm
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Password Manager XP - {7379d689-cc96-451d-b46e-6bbe4ca6b02d} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108173664123
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125851434899
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - http://www.photodex.com/pxplay.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11648 bytes
Kaspersy log
------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 7:33:38 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/06/2008
Kaspersky Anti-Virus database records: 827768
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 268389
Number of viruses found: 20
Number of infected objects: 78
Number of suspicious objects: 0
Duration of the scan process: 05:05:51
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-06-03_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\114F5CE0.tmp Infected: Flooder.Linux.Nestea.c skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\141271F4.tmp Infected: DoS.Linux.Kod.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\180F2ED2.tmp Infected: Flooder.Linux.Small.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\199766B6.exe Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FDF68F0.exe Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26CE502B.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27AC69AB.exe Infected: Trojan.Win32.Dialer.it skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A4A7CC6.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BC82D22.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BCF011B.tmp Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C863051.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40B015AF.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\483255D2.tmp Infected: Email-Worm.Win32.Klez.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4ACD0C18.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4AD13615.tmp Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E5F08F3.dll Infected: Trojan-Spy.Win32.Delf.jq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5157719E.emf Infected: Trojan-Downloader.Win32.Agent.acd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\566B342B.tmp Infected: Email-Worm.Win32.Klez.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57554FB9.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5DD70CD1.tmp Infected: Spoofer.Linux.Small.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BC7629D.tmp Infected: Exploit.Linux.Bonk.c skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\21410A55.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\5E35E9AC.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\All Users\ntuser.dat Object is locked skipped
C:\Documents and Settings\All Users\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\cert8.db Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\history.dat Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\key3.db Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-37bce4fc ZIP: infected - 2 skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Me\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-7f5b730e.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Me\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\ATI\ACE\Log\MOM-0.log Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Feeds\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Application Data\Mozilla\Firefox\Profiles\tkyahf2s.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Me\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\History\History.IE5\MSHist012008060320080604\index.dat Object is locked skipped
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\FBBYVSMN\css4[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Me\ntuser.dat Object is locked skipped
C:\Documents and Settings\Me\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\poop\!work\hacked file\sdf.txt Infected: Exploit.PHP.Deftool.e skipped
C:\poop\byXQKbaX.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab/is155083.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab/file.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip/AVG Anti Virus 8 Pro Key.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.vqj skipped
C:\poop\xnews\downloads\AVG Anti Virus 8 Pro Key.zip ZIP: infected - 8 skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip/AVG Anti-Virus 8 Pro Serial.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Anti-Virus 8 Pro Serial.zip ZIP: infected - 8 skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials\AVG Internet Security 8 Serials.exe Rsrc-Package: infected - 7 skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab/WMAPLA~1.EXE Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/Keygen.exe Infected: Trojan-Downloader.Win32.Small.wbx skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab/is155013.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab/file.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe/data0000.cab Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip/AVG Internet Security 8 Serials.exe Infected: Trojan-Downloader.Win32.Agent.rip skipped
C:\poop\xnews\downloads\AVG Internet Security 8 Serials.zip ZIP: infected - 8 skipped
C:\Program Files\CB Bar\cbbar.dll Infected: Trojan-Clicker.Win32.Delf.bc skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080603-193936-847.dll Infected: Trojan.Win32.Monder.lm skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080603-215745-112.dll Infected: Trojan.Win32.Monder.lm skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5541\NAV2007RETAIL_XP_VISTA32.64\NAV07RT.exe Infected: Trojan-Dropper.Win32.Agent.cuj skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe/data0000.cab/is200079.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar/PC Satellite Tv 2007 Elite Edition/setup.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-861567501-839522115-1004\Dc5555.rar RAR: infected - 3 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\A0207141.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\A0207227.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{78CF4A63-55A1-458A-8622-AA4D5B7D4CD4}\RP1985\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\byXNeCst.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ddcArSIc.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\ddcCSKAt.dll Infected: Trojan.Win32.Monder.lm skipped
C:\WINDOWS\system32\drivers\etc\Hosts.bak Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\JET2FC3.tmp Object is locked skipped
C:\WINDOWS\temp\JET460A.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Please help asap... Thanks for this. :)