reports
Hi Shaba, sorry for de delayed on this reports but as you can see it took more than 7 hours to do the scan.

Here it goes the report from kaspery (it look likes i'll have to do a scan with my avg antivirus ) and a fresh hijackThis log.
thanks for the help !!
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, October 16, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, October 16, 2008 08:52:28
Records in database: 1315286
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
M:\
Scan statistics:
Files scanned: 134131
Threat name: 44
Infected objects: 343
Suspicious objects: 0
Duration of the scan: 07:17:57
File name / Threat name / Threats count
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Casa\Desktop\11\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Casa\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Abnardella_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Adventureous_spirit_Buy_IncreaseSpermCount.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Alidatulian_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Beck_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Boggs_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Buddy1237-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_DIET_SENSATION.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_ExplodingOrgasm-BiggerLoads.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Buy_ExplodingOrgasms.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_GREAT_MALENLARGER.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_GUARANTEEDENLARGER.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_HERBALVIAGRA.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_LASTLONGER.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_LAST_LONGER.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_MultiOrgasms.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_PERMANENT_ENLARG.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Carminaherrera_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Carminaherrera_click_LAST-LONGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Chantal_89_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\click-WeightLossSensation.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Conejobustos_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Farris_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Frankmadero_click-sdrfs.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Frtrus.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Gcaldera31_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Hamlin_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Hogue_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Jesines-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Jlaws27_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Krmuska182_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Krmuska182_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Lorettab4_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Lori_last_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mackey_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mayram56_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mgaby11_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mmary84_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Moreno_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\OpenThisHTML_3DayDeliveryRXmed.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\OpenThisHTML_FastDeliveryRXmed.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Osborne_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Paulomarques84_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Paulomarques84_click-ONLINE_PHARM.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Perlunix_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Pmc49_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Pmc49_click_PERMANENTGrowth.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Pompier80_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Remacost_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Saeconsultores_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Saeconsultores_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Saeconsultores_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Sbrittonga_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Shannon_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Stahl_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Toan_alex_nguyen_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Unforgiv3n_click-BiggerLoads.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Unforgiv3n_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Wellsburggirl_Buy_Last-Longer.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Yutsc_click_LASTLONGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Zerosklero-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{01C8D34D-DF5D-463E-8CD2-E911826231F2}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{075899CB-20B2-407F-904B-BF952A5230CC}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{0E7C65B6-CD51-4DC4-A2BC-6CDB5A7D09C6}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{2D60A64E-E25D-4FB9-86AE-F16EB0D0A9FB}\Chantal_89_click-onlineRX.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{354C5E39-0E90-477C-9217-82998227E73E}\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{36822013-9908-42E6-B647-752E27CB4752}\Lorettab4_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{5C402DBB-BC46-4548-B3E5-5E947B4E3501}\Saeconsultores_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{65D1C754-A492-454A-99E1-48B877843A87}\Saeconsultores_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{71B68522-D715-4062-9184-B142BCA1CC1A}\Buy_Rx_Here.html Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{8A3E94EC-ECAE-4D43-8E1D-40FEE42FAABA}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{927AE709-00FF-4BE0-A7F7-2D4FFBA9D24E}\Lori_last_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{93E04E5C-84C0-468E-A5FC-05BE0728B3BC}\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{95FB89A0-A70A-4725-A645-469075A9D098}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{AC624000-90DF-48E1-AA27-2BA3CED1D596}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{C018DE05-6F18-4C56-886F-F1693CC9AD28}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\Local Settings\Application Data\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{C4F9D6B9-045C-4316-9147-AF9B9C114589}\BUY_MultiOrgasms.HTM Infected: Trojan.JS.Redirector.b 1
C:\Documents and Settings\Casa\My Documents\Downloads\Acronis Disk Director Server v10.0 Build 2169 [h33t] [Original]\diskdirectorserver100b2169en1.rar Infected: Trojan-Downloader.Win32.Delf.mmt 1
C:\Documents and Settings\Casa\My Documents\Downloads\Moyea.FLV.To.Video.Converter.Pro.v1.29.2.11.WinAll.Regged-PALACE\FLV2Video_Install.exe Infected: Trojan.Win32.Monder.gen 1
C:\Documents and Settings\Casa\My Documents\Downloads\Moyea.FLV.To.Video.Converter.Pro.v1.29.2.11.WinAll.Regged-PALACE\FLV2Video_Install.exe Infected: Trojan.Win32.Pakes.cgn 1
C:\Films\subtitles\the chronicles of narnia - the lion, the witch, and the wardrobe part 1e 2 .sub portuguese\the chronicles of narnia - the lion, the witch, and the wardrobe part 1.sub portuguese.zip Infected: Trojan-Downloader.WMA.Wimad.d 1
D:\DISCO C E DESKTOP\Disco C.zip Infected: Trojan.JS.Redirector.b 28
D:\DISCO C E DESKTOP\IncrediMail Transferred Data\IncrediMail Data.cab Infected: Trojan.JS.Redirector.b 3
D:\DISCO C E DESKTOP\IncrediMail Transferred Data\IncrediMail Data1.cab Infected: Trojan.JS.Redirector.b 3
D:\DISCO C E DESKTOP\IncrediMail Transferred Data\IncrediMail Data2.cab Infected: Trojan.JS.Redirector.b 3
D:\DISCO C E DESKTOP\IncrediMail Transferred Data\IncrediMail Data3.cab Infected: Trojan.JS.Redirector.b 3
D:\Films\subtitles\the chronicles of narnia - the lion, the witch, and the wardrobe part 1e 2 .sub portuguese\the chronicles of narnia - the lion, the witch, and the wardrobe part 1.sub portuguese.zip Infected: Trojan-Downloader.WMA.Wimad.d 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Abnardella_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Alidatulian_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Beck_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Boggs_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Buddy1237-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_DIET_SENSATION.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_ExplodingOrgasm-BiggerLoads.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Buy_ExplodingOrgasms.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_GREAT_MALENLARGER.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_GUARANTEEDENLARGER.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_HERBALVIAGRA.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_LASTLONGER.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_LAST_LONGER.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_MultiOrgasms.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_PERMANENT_ENLARG.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Carminaherrera_click_LAST-LONGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\click-WeightLossSensation.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Conejobustos_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Farris_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Frankmadero_click-sdrfs.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Frtrus.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Gcaldera31_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Hamlin_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Hogue_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Jesines-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Jlaws27_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Krmuska182_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Lorettab4_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Lori_last_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mackey_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Mmary84_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Moreno_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\OpenThisHTML_3DayDeliveryRXmed.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\OpenThisHTML_FastDeliveryRXmed.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Osborne_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Paulomarques84_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Paulomarques84_click-ONLINE_PHARM.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Perlunix_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Pmc49_click_PERMANENTGrowth.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Pompier80_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Remacost_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Saeconsultores_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Shannon_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Stahl_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Toan_alex_nguyen_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Unforgiv3n_click-BiggerLoads.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Wellsburggirl_Buy_Last-Longer.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Yutsc_click_LASTLONGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\Zerosklero-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{01C8D34D-DF5D-463E-8CD2-E911826231F2}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{075899CB-20B2-407F-904B-BF952A5230CC}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{0E7C65B6-CD51-4DC4-A2BC-6CDB5A7D09C6}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{354C5E39-0E90-477C-9217-82998227E73E}\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{36822013-9908-42E6-B647-752E27CB4752}\Lorettab4_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{8A3E94EC-ECAE-4D43-8E1D-40FEE42FAABA}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{927AE709-00FF-4BE0-A7F7-2D4FFBA9D24E}\Lori_last_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{93E04E5C-84C0-468E-A5FC-05BE0728B3BC}\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{95FB89A0-A70A-4725-A645-469075A9D098}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{AC624000-90DF-48E1-AA27-2BA3CED1D596}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{C018DE05-6F18-4C56-886F-F1693CC9AD28}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM\IM\Identities\{BE1587C5-0527-4641-BFA4-3A646EDD576F}\Message Store\Attachments\{C4F9D6B9-045C-4316-9147-AF9B9C114589}\BUY_MultiOrgasms.HTM Infected: Trojan.JS.Redirector.b 1
D:\Incredimail\IM.zip Infected: Trojan.JS.Redirector.b 42
D:\Incredimail\IncrediMail Data2.cab Infected: Trojan.JS.Redirector.b 8
D:\Programas\Longhorn\RockXP4.zip Infected: not-a-virus

SWTool.Win32.PWDump.2 2
D:\Programas\Longhorn\RockXP4.zip Infected: not-a-virus

SWTool.Win32.RAS.a 1
D:\Programas\Programas\bsplayer\bsplayer141.832.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\desktop search tools\vmntoolbox.exe Infected: not-a-virus:AdWare.Win32.BHO.byo 1
D:\Programas\Programas\FTP Servers\aceftp3\aceftp3free.exe Infected: not-a-virus:AdWare.Win32.BHO.ajt 1
D:\Programas\Programas\games\PacMan\FishTales.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\PacMan\FishTales.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\PacMan\Magic_Pets.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\PacMan\Magic_Pets.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\PacMan\PacManic.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\PacMan\PacManic.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\PacMan\PacManic_Christmas.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\PacMan\PacManic_Christmas.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\Screensaver\Amazon_Waterfall_Screensaver\Amazon_Waterfall_Screensaver.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\Screensaver\Amazon_Waterfall_Screensaver\Amazon_Waterfall_Screensaver.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\Screensaver\Aquarium_Screensaver\Aquarium_Screensaver.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\Screensaver\Aquarium_Screensaver\Aquarium_Screensaver.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\Screensaver\Christmas_Night_Screensaver\Christmas_Night_Screensaver.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\Screensaver\Christmas_Night_Screensaver\Christmas_Night_Screensaver.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\games\Screensaver\Sea_Castle_Screensaver\Sea_Castle_Screensaver.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
D:\Programas\Programas\games\Screensaver\Sea_Castle_Screensaver\Sea_Castle_Screensaver.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\ie 7\ie7\Add Ons\vmntoolbox.exe Infected: not-a-virus:AdWare.Win32.BHO.byo 1
D:\Programas\Programas\incredimail\PhotoJoy\PhotoJoy_Install.exe Infected: not-a-virus

ownloader.Win32.ImLoader.o 1
D:\Programas\Programas\MSN\Msn Live Messenger 8\Setup.exe Infected: not-a-virus:AdWare.Win32.180Solutions.as 1
D:\Programas\Programas\MSN\Msn Live Messenger 8\SmileyCentralPFSetup2.1.50.3-3.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.as 1
D:\Programas\Programas\Screensavers\sinstaller2(2).exe Infected: not-a-virus:AdWare.Win32.Comet.ac 1
D:\Programas\Programas\Stardock\themes\105063.exe Infected: not-a-virus:AdWare.Win32.EZula.z 1
D:\Programas\Programas\Stardock\themes\tcf1464.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
D:\Programas\Programas\Stardock\themes\tcf1464.exe Infected: not-a-virus:AdWare.Win32.Gator.3103 1
D:\Programas\Programas\Stardock\themes\tcf1464.exe Infected: not-a-virus:AdWare.Win32.EZula.z 1
D:\Programas\Programas\Stardock\themes\tcf1464.exe Infected: Trojan-Dropper.Win32.Agent.pd 1
D:\Programas\Programas\Varios\mailpv.zip Infected: not-a-virus

SWTool.Win32.MailPassView.e 1
D:\Programas\Programas\Varios\MSN-Password-Recovery-setup.exe Infected: not-a-virus

SWTool.Win32.MSNPassword.e 1
D:\Programas\Vista\Vista\5\Vista Transformation Pack 5.5.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\6\vtp6(1).zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\6\vtp6(1).zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\6\vtp6.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\6\vtp6.zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\6\vtp61.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\6\vtp61.zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\unziped\Vista Transformation Pack 3.0.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\unziped2\Vista Transformation Pack 3.0.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\unziped2\Vista Transformation Pack 4.0.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\Vista Transformation Pack\Vista Transformation Pack.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\Vista Transformation Pack\Vista_Transformation_Pack_4.0.rar Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\Vista Transformation Pack\vtp3.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\Vista Transformation Pack\vtp4.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\vitrans.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\vitrans2.0.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\vitrans_lite.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\vtp5_5.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.a 2
D:\Programas\Vista\Vista\vtp6(1)\Vista Transformation Pack 6.0.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\vtp6(1)\Vista Transformation Pack 6.0.exe Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\vtp6(1)\vtp6.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\vtp6(1)\vtp6.zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\vtp6(1).zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\vtp6(1).zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\vtp6.zip Infected: not-a-virus:RiskTool.Win32.CloseApp.e 2
D:\Programas\Vista\Vista\vtp6.zip Infected: Trojan-Spy.Win32.Agent.ehl 1
D:\Programas\Vista\Vista\vtp8\extras\FastAero\FastAero_0751f_eng0.121 Infected: Trojan-Downloader.Win32.Banload.tvg 1
D:\Shared Folder\Completos\Programs\Microsoft\Windows\Descodificador Tvcabo Para Winxp Compativel Com Pinnacle.ace Infected: Trojan.Win32.VB.ef 6
D:\Shared Folder\Completos\Programs\Microsoft\Windows\Descodificador Tvcabo Para Winxp Compativel Com Pinnacle.ace Infected: not-a-virus:AdWare.Win32.Aureate.a 5
D:\Shared Folder\Completos\Programs\Microsoft\Windows\Descodificador Tvcabo Para Winxp Compativel Com Pinnacle.zip Infected: Trojan.Win32.VB.ef 4
D:\Shared Folder\Completos\Programs\Microsoft\Windows\Descodificador Tvcabo Para Winxp Compativel Com Pinnacle.zip Infected: not-a-virus:AdWare.Win32.Aureate.a 5
The selected area was scanned.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:20:16, on 17-10-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\ViOrb\ViOrb.exe
C:\Program Files\LClock\lclock.exe
C:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Documents and Settings\Casa\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.netcabo.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.1852\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: The Lynx Internet Radio Network Toolbar - {cb90f295-4524-4bd4-adb4-8dc333d67d6a} - C:\Program Files\The_Lynx_Internet_Radio_Network\tbThe_.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand203000013.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: The Lynx Internet Radio Network Toolbar - {cb90f295-4524-4bd4-adb4-8dc333d67d6a} - C:\Program Files\The_Lynx_Internet_Radio_Network\tbThe_.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Opware12] "C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [IME JPN 2007 Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE /Preload
O4 - HKLM\..\Run: [Microsoft Pinyin IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe
O4 - HKCU\..\Run: [VisualTaskTips] C:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Styler.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: Add to Local Website Archive - C:\Documents and Settings\Casa\Application Data\aignes\Local Website Archive\config\iearc.htm
O8 - Extra context menu item: Add to WebSite-Watcher - C:\Documents and Settings\Casa\Application Data\aignes\WebSite-Watcher\config\settings\wswie.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {298C0B4F-3330-4F82-A2B0-75CB87AC3E97} - C:\Program Files\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra 'Tools' menuitem: Add to Local Website Archive - {298C0B4F-3330-4F82-A2B0-75CB87AC3E97} - C:\Program Files\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra button: Add to Local Website Archive - {651B27BB-07F3-46F6-91E2-73F48BDC7525} - C:\Program Files\Local Website Archive\wsarc_add.exe (HKCU)
O9 - Extra button: Add to Local Website Archive - {BAD3887C-C44F-436A-BE7E-184C47E66D09} - C:\Program Files\Local Website Archive\wsarc.exe (HKCU)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
--
End of file - 12747 bytes