HI
Is this a dual boot machine ? do you have another XP O\S in your E:\ drive ?
Find & delete this file :-
C:\WINDOWS\system32\iphckagb.dll
Then please run a new KASPERSKY ON-LINE scan & post the new log ...
steam
HI
Is this a dual boot machine ? do you have another XP O\S in your E:\ drive ?
Find & delete this file :-
C:\WINDOWS\system32\iphckagb.dll
Then please run a new KASPERSKY ON-LINE scan & post the new log ...
steam
MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E
no its not a dual boot machine
------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 17, 2007 5:16:15 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/11/2007
Kaspersky Anti-Virus database records: 460858
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 89936
Number of viruses found: 11
Number of infected objects: 66
Number of suspicious objects: 0
Duration of the scan process: 02:53:08
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped
C:\Documents and Settings\home\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\cert8.db Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\history.dat Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\key3.db Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\parent.lock Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\search.sqlite Object is locked skipped
C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\home\Application Data\Sony Ericsson\Teleca\Telecalib\Logging\Application logs\FM_log.txt Object is locked skipped
C:\Documents and Settings\home\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\home\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\Working\database_8A74_3FC1_743F_AEB7\dfsr.db Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\Working\database_8A74_3FC1_743F_AEB7\fsr.log Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\Working\database_8A74_3FC1_743F_AEB7\fsrtmp.log Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Messenger\stuarthend@hotmail.com\SharingMetadata\Working\database_8A74_3FC1_743F_AEB7\tmp.edb Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Microsoft\Windows Live Contacts\stuarthend@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\home\Local Settings\Application Data\Mozilla\Firefox\Profiles\6dwgxii1.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\home\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\home\Local Settings\History\History.IE5\MSHist012007111720071118\index.dat Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temp\fla13BE.tmp Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temp\hsperfdata_home\1980 Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temp\~DF9261.tmp Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temp\~DF926D.tmp Object is locked skipped
C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\home\My Documents\kiss now\app.log Object is locked skipped
C:\Documents and Settings\home\My Documents\kiss now\eventbroker.log Object is locked skipped
C:\Documents and Settings\home\My Documents\kiss now\kissnow.log Object is locked skipped
C:\Documents and Settings\home\My Documents\kiss now\net.log Object is locked skipped
C:\Documents and Settings\home\My Documents\kiss now\runtime.log Object is locked skipped
C:\Documents and Settings\home\ntuser.dat Object is locked skipped
C:\Documents and Settings\home\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\download\300.2006.1080p.BluRay.x264-hV\300.2006.1080p.bluray.x264-hv.part104.rar Object is locked skipped
C:\download\DivoCodec-1.3.0.0-setup-0712.exe.part/file4 Infected: Trojan.Win32.Obfuscated.en skipped
C:\download\DivoCodec-1.3.0.0-setup-0712.exe.part Inno: infected - 1 skipped
C:\download\UltraVNC-102-Setup.exe/file04 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\download\UltraVNC-102-Setup.exe/file05 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\download\UltraVNC-102-Setup.exe/file34 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\download\UltraVNC-102-Setup.exe Inno: infected - 3 skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-11-15.17-57-49.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.az skipped
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.az skipped
C:\Program Files\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped
C:\Program Files\UltraVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\Program Files\UltraVNC\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\aqkpvsox.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\axjffnpm.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dihijibt.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\iiygaxre.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\jcohfjca.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\jrckcbmf.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kggkxqmw.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kmhavjhl.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\lsopnhco.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mvonqjqg.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sdyghndc.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sedqqcgs.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\tatwbdam.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wpdprwfm.dll.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c00135F4.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c0048F84.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c004B90E.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c005FB00.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c0085324.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c0086E10.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c0097E71.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c009C4DC.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c00D1510.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\__c00EDEEC.dat.vir Infected: Trojan-Downloader.Win32.ConHook.hl skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E868635C-B618-4A88-B86D-424CBDCB2E66}\RP285\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_598.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_654.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\downloads\DivoCodec-1.3.0.0-setup-0712.exe.part/file4 Infected: Trojan.Win32.Obfuscated.en skipped
D:\downloads\DivoCodec-1.3.0.0-setup-0712.exe.part Inno: infected - 1 skipped
D:\downloads\UltraVNC-102-Setup.exe/file04 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
D:\downloads\UltraVNC-102-Setup.exe/file05 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
D:\downloads\UltraVNC-102-Setup.exe/file34 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
D:\downloads\UltraVNC-102-Setup.exe Inno: infected - 3 skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\download\Nero.Ultra.Edition.v8.0.3.0.Retail-ZWTiSO\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\download\Nero.Ultra.Edition.v8.0.3.0.Retail-ZWTiSO\nue8.0.3.0r.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\download\Nero.Ultra.Edition.v8.0.3.0.Retail-ZWTiSO\nue8.0.3.0r.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\download\Nero.Ultra.Edition.v8.0.3.0.Retail-ZWTiSO\nue8.0.3.0r.iso ISO image: infected - 3 skipped
E:\download\Office 2007 Key Gen.rar/Office 2007 Key Gen/MicrosoftOfficeKeyGen.exe Infected: Backdoor.Win32.VB.bce skipped
E:\download\Office 2007 Key Gen.rar RAR: infected - 1 skipped
E:\download\PC.Tools.Registry.Mechanic.v7.1.0.1010.Incl.Crack-CFF\rminstall.exe Infected: Backdoor.Win32.IRCBot.aok skipped
E:\old h drive\download\keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\keyfinder.exe RarSFX: infected - 3 skipped
E:\old h drive\download\kf141.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\kf141.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\kf141.zip/keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\kf141.zip/keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\old h drive\download\kf141.zip ZIP: infected - 4 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{893CE42B-E29C-403D-B83B-741AF67E01BD}\RP240\A0033982.exe/data0000.cab/Server.exe Infected: Backdoor.Win32.Dragonbot.k skipped
E:\System Volume Information\_restore{893CE42B-E29C-403D-B83B-741AF67E01BD}\RP240\A0033982.exe/data0000.cab Infected: Backdoor.Win32.Dragonbot.k skipped
E:\System Volume Information\_restore{893CE42B-E29C-403D-B83B-741AF67E01BD}\RP240\A0033982.exe Rsrc-Package: infected - 2 skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\HelixSDK RM converter kit for WinAVI.exe/data0000.cab/HELIXS~1.EXE Infected: Trojan-Downloader.Win32.Small.fuq skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\HelixSDK RM converter kit for WinAVI.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.fuq skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\HelixSDK RM converter kit for WinAVI.exe Rsrc-Package: infected - 2 skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\WinAVI_Video_Converter 8.0.exe/data0000.cab/WINAVI~1.EXE Infected: Trojan-Downloader.Win32.Small.fuq skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\WinAVI_Video_Converter 8.0.exe/data0000.cab Infected: Trojan-Downloader.Win32.Small.fuq skipped
F:\movie's\WinAVI Video Converter 8.1.1 + serial+ working key\WinAVI_Video_Converter 8.0.exe Rsrc-Package: infected - 2 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{E868635C-B618-4A88-B86D-424CBDCB2E66}\RP285\change.log Object is locked skipped
Scan process completed.
Hi
As you can see from the KASPERSKY ONLINE SCANNER REPORT
Your drives are full of illegally cracked programs, key gens, serial gens etc, if you look through the log you can see that they all come with Trojans/virus ... if you are serious about keeping your computer clean, then you will look closely at the log and delete all those illegal programs ...
steam
MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E
This topic has been moved to archives.
If you need the thread re-opened, please send me a private message (pm) and provide a link to the closed topic.
Applies only to the original poster, anyone else with similar problems please start your own topic.
Thank you steamwiz.
Microsoft MVP Reconnect 2018-
Windows Insider MVP 2016-2018
Microsoft Consumer Security MVP 2006-2016