griffin_99
New member
Hello. I hope someone can help. On running Spybot it now freezes at the following point: "Running bot-check (128840/150537: Virtumonde.dll). The scan moves no further and I have to use Task Manager to quit the application. I have run the on-line virus scanner and it states I have a virus on my external hard drive. AVG does not pick this up! Any help with both these points would be very much appreciated. Many thanks.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:37, on 07/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166297886484
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166553113656
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file:///F:/Resources/IntraLaunch.CAB
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
--
End of file - 13652 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 07, 2008 8:13:02 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 743022
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
Scan Statistics:
Total number of scanned objects: 206861
Number of viruses found: 1
Number of infected objects: 0
Number of suspicious objects: 46
Duration of the scan process: 02:23:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012008050720080508\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFAFEB.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFB01B.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S7A3882D8.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/19 Feb 2004 23:03 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/24 Feb 2004 16:35 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/03 Mar 2004 19:22 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/07 Mar 2005 22:48 from sindens9@aol.com:Item Number 6515616977 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 00:34 from ebay@cheapersoftware.ltd.uk:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 14:32 from paul@younger69.freeserve.co.uk:Item Numbe.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 18:50 from olly.haywood@btinternet.com:Item Number 5.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 19:48 from andytaylor@macunlimited.net:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 19:48 from jon.rougeolle@uwe.ac.uk:Item Number 63594.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/23 Jan 2005 10:11 from james@altnoise.co.uk:Item Number 81623574.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 00:48 from ianandkate@hotmail.com:Item Number 635941.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 08:18 from carolyn_phil_05@hotmail.co.uk:Item Number.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 10:01 from omarsany@hotmail.com:Item Number 65057417.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 14:24 from mark.vout@btopenworld.com:Item Number 406.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 15:20 from trudidavies8@aol.com:Item Number 63595075.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Feb 2005 07:59 from jardines@vexation.freeserve.co.uk:Item Nu.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Feb 2005 10:07 from soo_jones@hotmail.com:Item Number 6507903.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/24 Feb 2005 23:14 from john@johnpallister.wanadoo.co.uk:Item # -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/24 Feb 2005 23:36 from coincollector18@btinternet.com:Item # - N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Feb 2005 08:49 from mgoodall@colt-telecom.com:Item # - Notifi.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/26 Feb 2005 15:27 from heatherstott22@yahoo.co.uk:Item Number 65.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 01:12 from buyer@nelson.demon.co.uk:Item Number 6370.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 23:04 from neil@digitalcinematics.co.uk:Item Number .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 23:16 from rjp343@bham.ac.uk:Item Number 6369723341 .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/28 Feb 2005 05:59 from mandyandbud@yahoo.com:Item Number 6369718.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/28 Feb 2005 07:26 from jaysubash@hotmail.com:Item Number 6513079.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 01:16 from old.g@ntlworld.com:Item Number 6370278599.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 01:27 from sidney.smith2@ntlworld.com:Item Number 63.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 09:28 from planetbenny@aol.com:Item Number 637027933.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 12:49 from ssengkho@hotmail.com:Item Number 63702771.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/10 Mar 2005 18:26 from stephen@cunningham6469.fsnet.co.uk:Item N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/10 Mar 2005 23:53 from electric_starfish32@hotmail.com:Item Numb.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:32 from kazley40@aol.com:Item Number 6374773261 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:44 from pandoras_box@talk21.com:Item Number 63747.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:59 from gussy3773@yahoo.co.uk:Item Number 6374777.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 19:09 from MARKREEVES2@HOTMAIL.COM:Item Number 63747.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 20:17 from sadodra@aol.com:Item Number 6374763855 - .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/15 Mar 2005 10:10 from charlie_a_robertson@btinternet.com:Item N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/30 Apr 2005 21:36 from Young678@hotmail.com:Item Number 63899124.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 May 2005 19:55 from alibongo68@hotmail.com:Item Number 639109.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 May 2005 20:06 from tmcgh@tiscali.co.uk:Item Number 638990909.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 May 2005 21:06 from bethygirl94@talk21.com:Item Number 639110.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/16 May 2005 23:25 from horizzontal@btopenworld.com:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Jun 2005 14:31 from banjo7@gmail.com:Item Number 6401085678 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Jun 2005 15:10 from deejay_amie@hotmail.com:Item Number 81956.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst MailMSMaill: suspicious - 45 skipped
L:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
L:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:48:37, on 07/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166297886484
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166553113656
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file:///F:/Resources/IntraLaunch.CAB
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
--
End of file - 13652 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 07, 2008 8:13:02 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 743022
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
Scan Statistics:
Total number of scanned objects: 206861
Number of viruses found: 1
Number of infected objects: 0
Number of suspicious objects: 46
Duration of the scan process: 02:23:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012008050720080508\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFAFEB.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFB01B.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S7A3882D8.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/19 Feb 2004 23:03 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/24 Feb 2004 16:35 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/03 Mar 2004 19:22 from aw-confirm@ebay.com:Your invoice for eBay.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/ebay Documents/07 Mar 2005 22:48 from sindens9@aol.com:Item Number 6515616977 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 00:34 from ebay@cheapersoftware.ltd.uk:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 14:32 from paul@younger69.freeserve.co.uk:Item Numbe.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 18:50 from olly.haywood@btinternet.com:Item Number 5.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 19:48 from andytaylor@macunlimited.net:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/22 Jan 2005 19:48 from jon.rougeolle@uwe.ac.uk:Item Number 63594.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/23 Jan 2005 10:11 from james@altnoise.co.uk:Item Number 81623574.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 00:48 from ianandkate@hotmail.com:Item Number 635941.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 08:18 from carolyn_phil_05@hotmail.co.uk:Item Number.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 10:01 from omarsany@hotmail.com:Item Number 65057417.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 14:24 from mark.vout@btopenworld.com:Item Number 406.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Jan 2005 15:20 from trudidavies8@aol.com:Item Number 63595075.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Feb 2005 07:59 from jardines@vexation.freeserve.co.uk:Item Nu.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Feb 2005 10:07 from soo_jones@hotmail.com:Item Number 6507903.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/24 Feb 2005 23:14 from john@johnpallister.wanadoo.co.uk:Item # -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/24 Feb 2005 23:36 from coincollector18@btinternet.com:Item # - N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/25 Feb 2005 08:49 from mgoodall@colt-telecom.com:Item # - Notifi.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/26 Feb 2005 15:27 from heatherstott22@yahoo.co.uk:Item Number 65.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 01:12 from buyer@nelson.demon.co.uk:Item Number 6370.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 23:04 from neil@digitalcinematics.co.uk:Item Number .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/27 Feb 2005 23:16 from rjp343@bham.ac.uk:Item Number 6369723341 .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/28 Feb 2005 05:59 from mandyandbud@yahoo.com:Item Number 6369718.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/28 Feb 2005 07:26 from jaysubash@hotmail.com:Item Number 6513079.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 01:16 from old.g@ntlworld.com:Item Number 6370278599.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 01:27 from sidney.smith2@ntlworld.com:Item Number 63.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 09:28 from planetbenny@aol.com:Item Number 637027933.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 Mar 2005 12:49 from ssengkho@hotmail.com:Item Number 63702771.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/10 Mar 2005 18:26 from stephen@cunningham6469.fsnet.co.uk:Item N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/10 Mar 2005 23:53 from electric_starfish32@hotmail.com:Item Numb.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:32 from kazley40@aol.com:Item Number 6374773261 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:44 from pandoras_box@talk21.com:Item Number 63747.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 18:59 from gussy3773@yahoo.co.uk:Item Number 6374777.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 19:09 from MARKREEVES2@HOTMAIL.COM:Item Number 63747.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/12 Mar 2005 20:17 from sadodra@aol.com:Item Number 6374763855 - .rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/15 Mar 2005 10:10 from charlie_a_robertson@btinternet.com:Item N.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/30 Apr 2005 21:36 from Young678@hotmail.com:Item Number 63899124.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 May 2005 19:55 from alibongo68@hotmail.com:Item Number 639109.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/02 May 2005 20:06 from tmcgh@tiscali.co.uk:Item Number 638990909.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 May 2005 21:06 from bethygirl94@talk21.com:Item Number 639110.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/16 May 2005 23:25 from horizzontal@btopenworld.com:Item Number 6.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Jun 2005 14:31 from banjo7@gmail.com:Item Number 6401085678 -.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst/Personal Folders/Inbox/saved-e-mails/PAYPAL Documents/05 Jun 2005 15:10 from deejay_amie@hotmail.com:Item Number 81956.rtf Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
L:\General Backup (favorites, documents, Outlook data, scans)\Outlook Backups\inboxbackup.pst MailMSMaill: suspicious - 45 skipped
L:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
L:\System Volume Information\_restore{80DC5C79-2A86-4CC1-9CD1-1BF7D6883F58}\RP574\change.log Object is locked skipped
Scan process completed.